CoreResponseStateManager in Apache MyFaces Trinidad 1.0.0 through 1.0.13, 1.2.x before 1.2.15, 2.0.x before 2.0.2, and 2.1.x before 2.1.2 might allow attackers to conduct deserialization attacks via a crafted serialized view state string.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| org.apache.myfaces.trinidad:trinidad(Maven) | 1.0.0 | N/A | N/A |
| org.apache.myfaces.trinidad:trinidad(Maven) | 1.2.0 | 1.2.15 | N/A |
| org.apache.myfaces.trinidad:trinidad(Maven) | 2.0.0 | 2.0.2 | N/A |
| org.apache.myfaces.trinidad:trinidad(Maven) | 2.1.0 | 2.1.2 | N/A |
CVSS Metrics