CVE Vulnerabilities

CVE-2013-4221

Published: Oct 10, 2013 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
6.8 IMPORTANT
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM

The default configuration of the ObjectRepresentation class in Restlet before 2.1.4 deserializes objects from untrusted sources using the Java XMLDecoder, which allows remote attackers to execute arbitrary Java code via crafted XML.

Affected Software

Name Vendor Start Version End Version
Restlet Restlet * 2.1.3 (including)
Restlet Restlet 2.1-milestone1 (including) 2.1-milestone1 (including)
Restlet Restlet 2.1-milestone2 (including) 2.1-milestone2 (including)
Restlet Restlet 2.1-milestone3 (including) 2.1-milestone3 (including)
Restlet Restlet 2.1-milestone4 (including) 2.1-milestone4 (including)
Restlet Restlet 2.1-milestone5 (including) 2.1-milestone5 (including)
Restlet Restlet 2.1-milestone6 (including) 2.1-milestone6 (including)
Restlet Restlet 2.1-rc1 (including) 2.1-rc1 (including)
Restlet Restlet 2.1-rc2 (including) 2.1-rc2 (including)
Restlet Restlet 2.1-rc3 (including) 2.1-rc3 (including)
Restlet Restlet 2.1-rc4 (including) 2.1-rc4 (including)
Restlet Restlet 2.1-rc5 (including) 2.1-rc5 (including)
Restlet Restlet 2.1-rc6 (including) 2.1-rc6 (including)
Restlet Restlet 2.1.0 (including) 2.1.0 (including)
Restlet Restlet 2.1.1 (including) 2.1.1 (including)
Restlet Restlet 2.1.2 (including) 2.1.2 (including)
Fuse ESB Enterprise 7.1.0 RedHat *
Fuse Management Console 7.1.0 RedHat *
Fuse MQ Enterprise 7.1.0 RedHat *
Red Hat JBoss A-MQ 6.0 RedHat *
Red Hat JBoss Fuse 6.0 RedHat *
Restlet Ubuntu artful *
Restlet Ubuntu bionic *
Restlet Ubuntu cosmic *
Restlet Ubuntu esm-apps/bionic *
Restlet Ubuntu esm-apps/xenial *
Restlet Ubuntu quantal *
Restlet Ubuntu raring *
Restlet Ubuntu saucy *
Restlet Ubuntu trusty *
Restlet Ubuntu utopic *
Restlet Ubuntu vivid *
Restlet Ubuntu wily *
Restlet Ubuntu xenial *
Restlet Ubuntu yakkety *
Restlet Ubuntu zesty *

References