PT-2016-6220 · Apache · Apache Myfaces Trinidad

Published

2016-10-03

·

Updated

2022-05-13

·

CVE-2016-5019

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache MyFaces Trinidad versions 1.0.0 through 1.0.13 Apache MyFaces Trinidad versions 1.2.x before 1.2.15 Apache MyFaces Trinidad versions 2.0.x before 2.0.2 Apache MyFaces Trinidad versions 2.1.x before 2.1.2
Description The issue allows attackers to conduct deserialization attacks via a crafted serialized view state string. This could potentially be exploited by sending a malicious string to the CoreResponseStateManager in Apache MyFaces Trinidad.
Recommendations For versions 1.0.0 through 1.0.13, update to a version after 1.0.13 to resolve the issue. For versions 1.2.x before 1.2.15, update to version 1.2.15 or later to resolve the issue. For versions 2.0.x before 2.0.2, update to version 2.0.2 or later to resolve the issue. For versions 2.1.x before 2.1.2, update to version 2.1.2 or later to resolve the issue. As a temporary workaround, consider restricting the input to the CoreResponseStateManager to prevent deserialization attacks via crafted serialized view state strings.

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-5019
GHSA-X7RC-4GQW-3Q6Q

Affected Products

Apache Myfaces Trinidad