Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The default configuration of the ObjectRepresentation class in Restlet before 2.1.4 deserializes objects from untrusted sources, which allows remote attackers to execute arbitrary Java code via a serialized object, a different vulnerability than CVE-2013-4221.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Restlet Framework Object Deserialization 远程代码执行漏洞
Vulnerability Description
Restlet是美国Restlet公司的一个轻量级的REST框架。该框架能够将Web站点和Web服务组装到一个统一的Web应用程序中。 Restlet 2.1.4之前的版本中的ObjectRepresentation类的默认配置中存在安全漏洞,该漏洞源于程序反序列化来自不可信资源的对象。远程攻击者可借助序列化的对象利用该漏洞执行任意Java代码。
CVSS Information
N/A
Vulnerability Type
N/A