← Back to CVE List

CVE-2013-4521

Published: 2020-02-06T16:15Z
Last Modified: 2024-11-21T01:55Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
RichFaces implementation in Nuxeo Platform 5.6.0 before HF27 and 5.8.0 before HF-01 does not restrict the classes for which deserialization methods can be called, which allows remote attackers to execute arbitrary code via crafted serialized data. NOTE: this vulnerability may overlap CVE-2013-2165. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt