Описание
The default configuration of the ObjectRepresentation class in Restlet before 2.1.4 deserializes objects from untrusted sources using the Java XMLDecoder, which allows remote attackers to execute arbitrary Java code via crafted XML.
| Релиз | Статус | Примечание |
|---|---|---|
| artful | ignored | end of life |
| bionic | ignored | end of standard support, was needed |
| cosmic | ignored | end of life |
| devel | DNE | |
| disco | DNE | |
| eoan | DNE | |
| esm-apps-legacy/xenial | needed | |
| esm-apps/bionic | needed | |
| esm-apps/xenial | ignored | end of ESM support, was needed |
| esm-infra-legacy/trusty | DNE | trusty/esm was DNE [trusty was needed] |
Показывать по
10
EPSS
Процентиль: 86%
0.02947
Низкий
7.5 High
CVSS2
Связанные уязвимости
nvd
почти 13 лет назад
The default configuration of the ObjectRepresentation class in Restlet before 2.1.4 deserializes objects from untrusted sources using the Java XMLDecoder, which allows remote attackers to execute arbitrary Java code via crafted XML.
debian
почти 13 лет назад
The default configuration of the ObjectRepresentation class in Restlet ...
github
больше 4 лет назад
Restlet is vulnerable to Arbitrary Java Code Execution via crafted XML
EPSS
Процентиль: 86%
0.02947
Низкий
7.5 High
CVSS2