Description
The default configuration of the ObjectRepresentation class in Restlet before 2.1.4 deserializes objects from untrusted sources, which allows remote attackers to execute arbitrary Java code via a serialized object, a different vulnerability than CVE-2013-4221.
Remediation
References
http://restlet.org/learn/2.1/changes
https://github.com/restlet/restlet-framework-java/issues/778
https://bugzilla.redhat.com/show_bug.cgi?id=999735
http://rhn.redhat.com/errata/RHSA-2013-1410.html
http://rhn.redhat.com/errata/RHSA-2013-1862.html
Related Vulnerabilities
CVE-2023-31417 Vulnerability in maven package org.elasticsearch:elasticsearch
CVE-2017-1000390 Vulnerability in maven package org.jenkins-ci.plugins:jenkins-multijob-plugin
CVE-2023-29014 Vulnerability in maven package io.goobi.viewer:viewer-core
CVE-2023-49446 Vulnerability in maven package com.jfinal:jfinal
CVE-2014-3579 Vulnerability in maven package org.apache.activemq:apollo-selector