Lucene search

K
osvGoogleOSV:GHSA-F3MV-G3XR-FP7W
HistoryMay 17, 2022 - 3:28 a.m.

Restlet Arbitrary Java Code Execution via a serialized object

2022-05-1703:28:57
Google
osv.dev
7

0.017 Low

EPSS

Percentile

87.8%

The default configuration of the ObjectRepresentation class in Restlet before 2.1.4 deserializes objects from untrusted sources, which allows remote attackers to execute arbitrary Java code via a serialized object, a different vulnerability than CVE-2013-4221.

0.017 Low

EPSS

Percentile

87.8%