GHSA-f3mv-g3xr-fp7w
Dashboard / Vulnerabilities / GHSA-f3mv-g3xr-fp7w
Summary: Restlet Arbitrary Java Code Execution via a serialized object
Details: The default configuration of the ObjectRepresentation class in Restlet before 2.1.4 deserializes objects from untrusted sources, which allows remote attackers to execute arbitrary Java code via a serialized object, a different vulnerability than CVE-2013-4221.
References: https://nvd.nist.gov/vuln/detail/CVE-2013-4271, https://github.com/restlet/restlet-framework-java/issues/778, https://bugzilla.redhat.com/show_bug.cgi?id=999735, https://github.com/restlet/restlet-framework-java, http://restlet.org/learn/2.1/changes, http://rhn.redhat.com/errata/RHSA-2013-1410.html, http://rhn.redhat.com/errata/RHSA-2013-1862.html
Affected packages
Package
Name: org.restlet.jse:org.restlet
Purl: pkg:maven/org.restlet.jse/org.restlet
Affected ranges
Type: ECOSYSTEM
Events:
