Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
RichFaces implementation in Nuxeo Platform 5.6.0 before HF27 and 5.8.0 before HF-01 does not restrict the classes for which deserialization methods can be called, which allows remote attackers to execute arbitrary code via crafted serialized data. NOTE: this vulnerability may overlap CVE-2013-2165.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Nuxeo 代码问题漏洞
Vulnerability Description
Nuxeo是Nuxeo开源的一个开源、可定制和可扩展的内容管理平台。用于构建业务应用程序。 Nuxeo 5.6.0版本至5.6.0 HF26版本和Nuxeo 5.8.0版本存在代码问题漏洞。远程攻击者可通过特制的序列化数据利用该漏洞执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A