CoreResponseStateManager in Apache MyFaces Trinidad 1.0.0 through 1.0.13, 1.2.x before 1.2.15, 2.0.x before 2.0.2, and 2.1.x before 2.1.2 might allow attackers to conduct deserialization attacks via a crafted serialized view state string.
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Myfaces_trinidad | Apache | 1.0.0 (including) | 1.0.13 (excluding) |
Myfaces_trinidad | Apache | 1.2.0 (including) | 1.2.15 (excluding) |
Myfaces_trinidad | Apache | 2.0.0 (including) | 2.0.2 (excluding) |
Myfaces_trinidad | Apache | 2.1.0 (including) | 2.1.2 (excluding) |