PT-2020-7502 · Nuxeo · Nuxeo Platform
Arun Neelicattu
+1
·
Published
2020-02-06
·
Updated
2020-02-13
·
CVE-2013-4521
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Nuxeo Platform versions 5.6.0 through 5.6.0 before HF27
Nuxeo Platform versions 5.8.0 through 5.8.0 before HF-01
Description:
The issue allows remote attackers to execute arbitrary code via crafted serialized data because the RichFaces implementation does not restrict the classes for which deserialization methods can be called.
Recommendations:
For Nuxeo Platform versions 5.6.0 through 5.6.0 before HF27, apply Hotfix 27 to resolve the issue.
For Nuxeo Platform versions 5.8.0 through 5.8.0 before HF-01, apply Hotfix 01 to resolve the issue.
Fix
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nuxeo Platform