Lucene search

K
prionPRIOn knowledge basePRION:CVE-2013-4521
HistoryFeb 06, 2020 - 4:15 p.m.

Deserialization of untrusted data

2020-02-0616:15:00
PRIOn knowledge base
www.prio-n.com
6

8.1 High

AI Score

Confidence

Low

0.1 Low

EPSS

Percentile

94.9%

RichFaces implementation in Nuxeo Platform 5.6.0 before HF27 and 5.8.0 before HF-01 does not restrict the classes for which deserialization methods can be called, which allows remote attackers to execute arbitrary code via crafted serialized data. NOTE: this vulnerability may overlap CVE-2013-2165.

8.1 High

AI Score

Confidence

Low

0.1 Low

EPSS

Percentile

94.9%