PT-2020-7502 · Nuxeo · Nuxeo Platform

Arun Neelicattu

+1

·

Published

2020-02-06

·

Updated

2020-02-13

·

CVE-2013-4521

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Nuxeo Platform versions 5.6.0 through 5.6.0 before HF27 Nuxeo Platform versions 5.8.0 through 5.8.0 before HF-01
Description: The issue allows remote attackers to execute arbitrary code via crafted serialized data because the RichFaces implementation does not restrict the classes for which deserialization methods can be called.
Recommendations: For Nuxeo Platform versions 5.6.0 through 5.6.0 before HF27, apply Hotfix 27 to resolve the issue. For Nuxeo Platform versions 5.8.0 through 5.8.0 before HF-01, apply Hotfix 01 to resolve the issue.

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-4521

Affected Products

Nuxeo Platform