First published: Mon Oct 03 2016(Updated: )
`CoreResponseStateManager` in Apache MyFaces Trinidad 1.0.0 through 1.0.13, 1.2.x before 1.2.15, 2.0.x before 2.0.2, and 2.1.x before 2.1.2 might allow attackers to conduct deserialization attacks via a crafted serialized viewstate string.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apache MyFaces Trinidad | >=1.0.0<1.0.13 | |
Apache MyFaces Trinidad | >=1.2.0<1.2.15 | |
Apache MyFaces Trinidad | >=2.0.0<2.0.2 | |
Apache MyFaces Trinidad | >=2.1.0<2.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.