GHSA-4344-frcp-j22q
HIGHCVE-2013-2165A flaw was found in the way JBoss RichFaces handled deserialization. A remote attacker could use this flaw to trigger the execution of the deserialization methods in any serializable class deployed on the server. This could lead to a variety of security impacts depending on the deserialization logic of these classes.
- Affected
- >= 3.1.0, < 3.3.3, >= 4.0.0, < 4.3.2
- Fixed in
- 3.3.3
- Published
- 2022-05-13
- Source
- github
GHSANVDMITREreferencereferencereferencereferencereferencereference