Description
The default configuration of the ObjectRepresentation class in Restlet before 2.1.4 deserializes objects from untrusted sources, which allows remote attackers to execute arbitrary Java code via a serialized object, a different vulnerability than CVE-2013-4221.
Remediation
References
http://restlet.org/learn/2.1/changes
http://rhn.redhat.com/errata/RHSA-2013-1410.html
http://rhn.redhat.com/errata/RHSA-2013-1862.html
https://bugzilla.redhat.com/show_bug.cgi?id=999735
https://github.com/restlet/restlet-framework-java/issues/778
Related Vulnerabilities
CVE-2013-5679 Vulnerability in maven package org.owasp.esapi:esapi
CVE-2012-0818 Vulnerability in maven package org.jboss.resteasy:resteasy-jettison-provider
CVE-2022-24762 Vulnerability in npm package sysend
CVE-2023-32071 Vulnerability in maven package org.xwiki.platform:xwiki-platform-web-templates
CVE-2023-26477 Vulnerability in maven package org.xwiki.platform:xwiki-platform-flamingo-theme-ui