CVE-2013-4521
Summary
| CVE | CVE-2013-4521 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-02-06 16:15:00 UTC |
| Updated | 2020-02-13 17:24:00 UTC |
| Description | RichFaces implementation in Nuxeo Platform 5.6.0 before HF27 and 5.8.0 before HF-01 does not restrict the classes for which deserialization methods can be called, which allows remote attackers to execute arbitrary code via crafted serialized data. NOTE: this vulnerability may overlap CVE-2013-2165. |
Risk And Classification
Problem Types: CWE-502
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Nuxeo | Nuxeo | 5.6.0 | - | All | All |
| Application | Nuxeo | Nuxeo | 5.6.0 | hotfix01 | All | All |
| Application | Nuxeo | Nuxeo | 5.6.0 | hotfix02 | All | All |
| Application | Nuxeo | Nuxeo | 5.6.0 | hotfix03 | All | All |
| Application | Nuxeo | Nuxeo | 5.6.0 | hotfix04 | All | All |
| Application | Nuxeo | Nuxeo | 5.6.0 | hotfix05 | All | All |
| Application | Nuxeo | Nuxeo | 5.6.0 | hotfix06 | All | All |
| Application | Nuxeo | Nuxeo | 5.6.0 | hotfix07 | All | All |
| Application | Nuxeo | Nuxeo | 5.6.0 | hotfix08 | All | All |
| Application | Nuxeo | Nuxeo | 5.6.0 | hotfix09 | All | All |
| Application | Nuxeo | Nuxeo | 5.6.0 | hotfix10 | All | All |
| Application | Nuxeo | Nuxeo | 5.6.0 | hotfix11 | All | All |
| Application | Nuxeo | Nuxeo | 5.6.0 | hotfix12 | All | All |
| Application | Nuxeo | Nuxeo | 5.6.0 | hotfix13 | All | All |
| Application | Nuxeo | Nuxeo | 5.6.0 | hotfix14 | All | All |
| Application | Nuxeo | Nuxeo | 5.6.0 | hotfix15 | All | All |
| Application | Nuxeo | Nuxeo | 5.6.0 | hotfix16 | All | All |
| Application | Nuxeo | Nuxeo | 5.6.0 | hotfix17 | All | All |
| Application | Nuxeo | Nuxeo | 5.6.0 | hotfix18 | All | All |
| Application | Nuxeo | Nuxeo | 5.6.0 | hotfix19 | All | All |
| Application | Nuxeo | Nuxeo | 5.6.0 | hotfix20 | All | All |
| Application | Nuxeo | Nuxeo | 5.6.0 | hotfix21 | All | All |
| Application | Nuxeo | Nuxeo | 5.6.0 | hotfix22 | All | All |
| Application | Nuxeo | Nuxeo | 5.6.0 | hotfix23 | All | All |
| Application | Nuxeo | Nuxeo | 5.6.0 | hotfix24 | All | All |
| Application | Nuxeo | Nuxeo | 5.6.0 | hotfix25 | All | All |
| Application | Nuxeo | Nuxeo | 5.6.0 | hotfix26 | All | All |
| Application | Nuxeo | Nuxeo | 5.8.0 | - | All | All |
| Application | Nuxeo | Nuxeo | 5.6.0 | - | All | All |
| Application | Nuxeo | Nuxeo | 5.6.0 | hotfix01 | All | All |
| Application | Nuxeo | Nuxeo | 5.6.0 | hotfix02 | All | All |
| Application | Nuxeo | Nuxeo | 5.6.0 | hotfix03 | All | All |
| Application | Nuxeo | Nuxeo | 5.6.0 | hotfix04 | All | All |
| Application | Nuxeo | Nuxeo | 5.6.0 | hotfix05 | All | All |
| Application | Nuxeo | Nuxeo | 5.6.0 | hotfix06 | All | All |
| Application | Nuxeo | Nuxeo | 5.6.0 | hotfix07 | All | All |
| Application | Nuxeo | Nuxeo | 5.6.0 | hotfix08 | All | All |
| Application | Nuxeo | Nuxeo | 5.6.0 | hotfix09 | All | All |
| Application | Nuxeo | Nuxeo | 5.6.0 | hotfix10 | All | All |
| Application | Nuxeo | Nuxeo | 5.6.0 | hotfix11 | All | All |
| Application | Nuxeo | Nuxeo | 5.6.0 | hotfix12 | All | All |
| Application | Nuxeo | Nuxeo | 5.6.0 | hotfix13 | All | All |
| Application | Nuxeo | Nuxeo | 5.6.0 | hotfix14 | All | All |
| Application | Nuxeo | Nuxeo | 5.6.0 | hotfix15 | All | All |
| Application | Nuxeo | Nuxeo | 5.6.0 | hotfix16 | All | All |
| Application | Nuxeo | Nuxeo | 5.6.0 | hotfix17 | All | All |
| Application | Nuxeo | Nuxeo | 5.6.0 | hotfix18 | All | All |
| Application | Nuxeo | Nuxeo | 5.6.0 | hotfix19 | All | All |
| Application | Nuxeo | Nuxeo | 5.6.0 | hotfix20 | All | All |
| Application | Nuxeo | Nuxeo | 5.6.0 | hotfix21 | All | All |
| Application | Nuxeo | Nuxeo | 5.6.0 | hotfix22 | All | All |
| Application | Nuxeo | Nuxeo | 5.6.0 | hotfix23 | All | All |
| Application | Nuxeo | Nuxeo | 5.6.0 | hotfix24 | All | All |
| Application | Nuxeo | Nuxeo | 5.6.0 | hotfix25 | All | All |
| Application | Nuxeo | Nuxeo | 5.6.0 | hotfix26 | All | All |
| Application | Nuxeo | Nuxeo | 5.8.0 | - | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 1027052 – (CVE-2013-4521) CVE-2013-4521 Nuxeo RichFaces: Remote code execution due to insecure deserialization | MISC | bugzilla.redhat.com | Issue Tracking, Patch, Third Party Advisory |
| NXBT-661: apply patch for CVE-2013-4521 flaw · nuxeo/richfaces-3.3@6cbad2a · GitHub | CONFIRM | github.com | Patch, Third Party Advisory |
| Nuxeo Security Hotfixes - Nuxeo Installation and Administration - 5.8 - Nuxeo Documentation Center | CONFIRM | doc.nuxeo.com | Broken Link, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.