← Back

Nuxeo

nuxeo

2 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Nuxeo
nuxeo

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Nuxeo
1Nuxeo
Nov 21, 2024
Feb 6, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
RichFaces implementation in Nuxeo Platform 5.6.0 before HF27 and 5.8.0 before HF-01 does not restrict the classes for which deserialization methods can be called, which allows remote attackers to execute arbitrary code v...Show more
RichFaces implementation in Nuxeo Platform 5.6.0 before HF27 and 5.8.0 before HF-01 does not restrict the classes for which deserialization methods can be called, which allows remote attackers to execute arbitrary code via crafted serialized data. NOTE: this vulnerability may overlap CVE-2013-2165.Show less
1Nuxeo
1Nuxeo
May 13, 2026
Mar 24, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Directory traversal vulnerability in the file import feature in Nuxeo Platform 6.0, 7.1, 7.2, and 7.3 allows remote authenticated users to upload and execute arbitrary JSP code via a .. (dot dot) in the X-File-Name heade...Show more
Directory traversal vulnerability in the file import feature in Nuxeo Platform 6.0, 7.1, 7.2, and 7.3 allows remote authenticated users to upload and execute arbitrary JSP code via a .. (dot dot) in the X-File-Name header.Show less