Lucene search

K
osvGoogleOSV:GHSA-X7RC-4GQW-3Q6Q
HistoryMay 13, 2022 - 1:25 a.m.

Apache MyFaces Trinidad Deserialization Vulnerability

2022-05-1301:25:19
Google
osv.dev
12

0.004 Low

EPSS

Percentile

72.8%

CoreResponseStateManager in Apache MyFaces Trinidad 1.0.0 through 1.0.13, 1.2.x before 1.2.15, 2.0.x before 2.0.2, and 2.1.x before 2.1.2 might allow attackers to conduct deserialization attacks via a crafted serialized viewstate string.

References

0.004 Low

EPSS

Percentile

72.8%