Lucene search

K
osvGoogleOSV:GHSA-4344-FRCP-J22Q
HistoryMay 13, 2022 - 1:27 a.m.

Remote code execution due to insecure deserialization

2022-05-1301:27:59
Google
osv.dev
9

0.1 Low

EPSS

Percentile

94.9%

A flaw was found in the way JBoss RichFaces handled deserialization. A remote attacker could use this flaw to trigger the execution of the deserialization methods in any serializable class deployed on the server. This could lead to a variety of security impacts depending on the deserialization logic of these classes.

0.1 Low

EPSS

Percentile

94.9%