HIGH
The default configuration of the ObjectRepresentation class in Restlet before 2.1.4 deserializes objects from untrusted sources using the Java XMLDecoder, which allows remote attackers to execute arbitrary Java code via crafted XML
Published Oct 10, 2013
7.5
HIGHCVSS 2.0
EPSS 3.39%
Description
The default configuration of the ObjectRepresentation class in Restlet before 2.1.4 deserializes objects from untrusted sources using the Java XMLDecoder, which allows remote attackers to execute arbitrary Java code via crafted XML.
Affected products
No data.
OR
- ≤ 2.1.3
- 2.1
- 2.1
- 2.1
- 2.1
- 2.1
- 2.1
- 2.1
- 2.1
- 2.1
- 2.1
- 2.1
- 2.1
- 2.1.0
- 2.1.1
- 2.1.2
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (9)
- http://blog.diniscruz.com/2013/08/using-xmldecoder-to-execute-server-side.html x_refsource_MISCThird Party Advisory
- http://restlet.org/learn/2.1/changes x_refsource_CONFIRMRelease NotesVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2013-1410.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2013-1862.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=995275 x_refsource_CONFIRMIssue TrackingThird Party Advisory
- https://github.com/advisories/GHSA-92j2-5r7p-6hjw Advisory
- https://github.com/restlet/restlet-framework-java/commit/b85c2ef182c69c5e2e21df008ccb249ccf80c7b
- https://github.com/restlet/restlet-framework-java/issues/774 x_refsource_CONFIRMIssue TrackingPatch
- https://nvd.nist.gov/vuln/detail/CVE-2013-4221
| Link | Providers | Tags |
|---|---|---|
| http://blog.diniscruz.com/2013/08/using-xmldecoder-to-execute-server-side.html | x_refsource_MISCThird Party Advisory | |
| http://restlet.org/learn/2.1/changes | x_refsource_CONFIRMRelease NotesVendor Advisory | |
| http://rhn.redhat.com/errata/RHSA-2013-1410.html | vendor-advisoryx_refsource_REDHATThird Party Advisory | |
| http://rhn.redhat.com/errata/RHSA-2013-1862.html | vendor-advisoryx_refsource_REDHATThird Party Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=995275 | x_refsource_CONFIRMIssue TrackingThird Party Advisory | |
| https://github.com/advisories/GHSA-92j2-5r7p-6hjw | Advisory | |
| https://github.com/restlet/restlet-framework-java/commit/b85c2ef182c69c5e2e21df008ccb249ccf80c7b | ||
| https://github.com/restlet/restlet-framework-java/issues/774 | x_refsource_CONFIRMIssue TrackingPatch | |
| https://nvd.nist.gov/vuln/detail/CVE-2013-4221 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Oct 10, 2013
Updated Aug 6, 2024
Reserved Jun 12, 2013
Link CVE-2013-4221
CISA Vulnrichment
GHSA-92J2-5R7P-6HJW Updated n/a