CVE-2013-4271
Restlet Arbitrary Java Code Execution via a serialized object
EPSS 0.49%
Description
The default configuration of the ObjectRepresentation class in Restlet before 2.1.4 deserializes objects from untrusted sources, which allows remote attackers to execute arbitrary Java code via a serialized object, a different vulnerability than CVE-2013-4221.
How to fix CVE-2013-4271
To remediate CVE-2013-4271, upgrade the affected package to a fixed version below.
- Maven/org.restlet.jse:org.restlet—upgrade to 2.1.4 or later
Is CVE-2013-4271 being exploited?
Low — EPSS is 0.5%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 2.1.4