← Back

CVE-2013-4521

nvd nist
Published: Feb 6, 2020Modified: Nov 21, 2024

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

RichFaces implementation in Nuxeo Platform 5.6.0 before HF27 and 5.8.0 before HF-01 does not restrict the classes for which deserialization methods can be called, which allows remote attackers to execute arbitrary code via crafted serialized data. NOTE: this vulnerability may overlap CVE-2013-2165.

Affected (28)

Products: Nuxeo: Nuxeo
1 product
Nuxeo
Configuration A
28 vulnerable
Vulnerable SoftwareAffected Versions
Nuxeo
Version 5.6.0
Version 5.6.0 hotfix01
Version 5.6.0 hotfix02
Version 5.6.0 hotfix03
Version 5.6.0 hotfix04
Version 5.6.0 hotfix05
Version 5.6.0 hotfix06
Version 5.6.0 hotfix07
Version 5.6.0 hotfix08
Version 5.6.0 hotfix09
Version 5.6.0 hotfix10
Version 5.6.0 hotfix11
Version 5.6.0 hotfix12
Version 5.6.0 hotfix13
Version 5.6.0 hotfix14
Version 5.6.0 hotfix15
Version 5.6.0 hotfix16
Version 5.6.0 hotfix17
Version 5.6.0 hotfix18
Version 5.6.0 hotfix19
Version 5.6.0 hotfix20
Version 5.6.0 hotfix21
Version 5.6.0 hotfix22
Version 5.6.0 hotfix23
Version 5.6.0 hotfix24
Version 5.6.0 hotfix25
Version 5.6.0 hotfix26
Version 5.8.0

References (6)

Source: secalert@redhat.com
Broken LinkVendor Advisory
Source: secalert@redhat.com
Issue TrackingPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory

Timeline

No history available yet.