CyberSec.Space Logo
CVEブラウザに戻る

CVE-2013-4221

HIGH
7.5
CVSS Severity Score
EPSS Score0.0090%
EPSS Percentile24.53th
Published2013年10月10日
Last Modified2026年4月29日

Vulnerability Description

The default configuration of the ObjectRepresentation class in Restlet before 2.1.4 deserializes objects from untrusted sources using the Java XMLDecoder, which allows remote attackers to execute arbitrary Java code via crafted XML.

Affected Platforms (CPE)

📦
Restlet

Restlet

<= 2.1.3
📦
Restlet

Restlet

= 2.1
📦
Restlet

Restlet

= 2.1
📦
Restlet

Restlet

= 2.1
📦
Restlet

Restlet

= 2.1
📦
Restlet

Restlet

= 2.1
📦
Restlet

Restlet

= 2.1
📦
Restlet

Restlet

= 2.1
📦
Restlet

Restlet

= 2.1
📦
Restlet

Restlet

= 2.1
📦
Restlet

Restlet

= 2.1
📦
Restlet

Restlet

= 2.1
📦
Restlet

Restlet

= 2.1
📦
Restlet

Restlet

= 2.1.0
📦
Restlet

Restlet

= 2.1.1
📦
Restlet

Restlet

= 2.1.2

References & Advisories

関連する脆弱性情報