Nuxeo Platform vulnerabilities
2 known vulnerabilities affecting nuxeo/nuxeo_platform.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2
Vulnerabilities
Page 1 of 1
CVE-2013-4521HIGHCVSS 7.5v5.6.0 before HF27v5.8.0 before HF-012020-02-06
CVE-2013-4521 [HIGH] CVE-2013-4521: RichFaces implementation in Nuxeo Platform 5
RichFaces implementation in Nuxeo Platform 5.6.0 before HF27 and 5.8.0 before HF-01 does not restrict the classes for which deserialization methods can be called, which allows remote attackers to execute arbitrary code via crafted serialized data. NOTE: this vulnerability may overlap CVE-2013-2165.
cvelistv5
CVE-2013-2165HIGHCVSS 7.5v5.6.0 before HF27v5.8.0 before HF-012013-07-23
CVE-2013-2165 [HIGH] CWE-264 CVE-2013-2165: ResourceBuilderImpl.java in the RichFaces 3.x through 5.x implementation in Red Hat JBoss Web Framew
ResourceBuilderImpl.java in the RichFaces 3.x through 5.x implementation in Red Hat JBoss Web Framework Kit before 2.3.0, Red Hat JBoss Web Platform through 5.2.0, Red Hat JBoss Enterprise Application Platform through 4.3.0 CP10 and 5.x through 5.2.0, Red Hat JBoss BRMS through 5.3.1, Red Hat JBoss SOA Platform through 4.3.0 CP05 and 5.x through 5.3.1,
nvd