CVE Vulnerabilities

CVE-2013-4221

Published: Oct 10, 2013 | Modified: Dec 07, 2016
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

The default configuration of the ObjectRepresentation class in Restlet before 2.1.4 deserializes objects from untrusted sources using the Java XMLDecoder, which allows remote attackers to execute arbitrary Java code via crafted XML.

Affected Software

Name Vendor Start Version End Version
Restlet Restlet * 2.1.3 (including)
Restlet Restlet 2.1-milestone1 (including) 2.1-milestone1 (including)
Restlet Restlet 2.1-milestone2 (including) 2.1-milestone2 (including)
Restlet Restlet 2.1-milestone3 (including) 2.1-milestone3 (including)
Restlet Restlet 2.1-milestone4 (including) 2.1-milestone4 (including)
Restlet Restlet 2.1-milestone5 (including) 2.1-milestone5 (including)
Restlet Restlet 2.1-milestone6 (including) 2.1-milestone6 (including)
Restlet Restlet 2.1-rc1 (including) 2.1-rc1 (including)
Restlet Restlet 2.1-rc2 (including) 2.1-rc2 (including)
Restlet Restlet 2.1-rc3 (including) 2.1-rc3 (including)
Restlet Restlet 2.1-rc4 (including) 2.1-rc4 (including)
Restlet Restlet 2.1-rc5 (including) 2.1-rc5 (including)
Restlet Restlet 2.1-rc6 (including) 2.1-rc6 (including)
Restlet Restlet 2.1.0 (including) 2.1.0 (including)
Restlet Restlet 2.1.1 (including) 2.1.1 (including)
Restlet Restlet 2.1.2 (including) 2.1.2 (including)

References