CVE-2013-4221
Restlet is vulnerable to Arbitrary Java Code Execution via crafted XML
EPSS 2.1%
Description
The default configuration of the ObjectRepresentation class in Restlet before 2.1.4 deserializes objects from untrusted sources using the Java XMLDecoder, which allows remote attackers to execute arbitrary Java code via crafted XML.
How to fix CVE-2013-4221
To remediate CVE-2013-4221, upgrade the affected package to a fixed version below.
- Maven/org.restlet.jse:org.restlet—upgrade to 2.1.4 or later
Is CVE-2013-4221 being exploited?
Low — EPSS is 2.1%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 2.1.4