First published: Sun Dec 15 2019(Updated: )
eDeploy has RCE via cPickle deserialization of untrusted data
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Edeploy | ||
Redhat Jboss Enterprise Web Server | =1.0.0 | |
debian/undefined |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-3699 is a vulnerability in eDeploy that allows remote code execution through the deserialization of untrusted data.
CVE-2014-3699 has a severity rating of critical.
CVE-2014-3699 affects Redhat Edeploy and can result in remote code execution.
CVE-2014-3699 impacts Redhat Jboss Enterprise Web Server 1.0.0 and can lead to remote code execution.
More information about CVE-2014-3699 can be found at the following references: [link1](https://access.redhat.com/security/cve/cve-2014-3699), [link2](https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2014-3699), [link3](https://security-tracker.debian.org/tracker/CVE-2014-3699).