nuxeo/richfaces-3.3

nuxeo/richfaces-3.3

Releases16
Frequency1 month 1 week
Last Release
Stars4
Fork of the richfaces 3.3.1.GA sources for patches needed by Nuxeo

CVE History

CVEPublishedCVSS v3CVSS v2
9.8 CRITICAL7.5 HIGH

RichFaces implementation in Nuxeo Platform 5.6.0 before HF27 and 5.8.0 before HF-01 does not restrict the classes for which deserialization methods can be called, which allows remote attackers to execute arbitrary code via crafted serialized data. NOTE: this vulnerability may overlap CVE-2013-2165.