CoreResponseStateManager in Apache MyFaces Trinidad 1.0.0 through 1.0.13, 1.2.x before 1.2.15, 2.0.x before 2.0.2, and 2.1.x before 2.1.2 might allow attackers to conduct deserialization attacks via a crafted serialized view state string.
{
"cpe": "cpe:2.3:a:apache:myfaces_trinidad:*:*:*:*:*:*:*:*",
"source": "CPE_RANGE",
"extracted_events": [
{
"introduced": "1.0.0"
},
{
"fixed": "1.0.13"
},
{
"introduced": "1.2.0"
},
{
"fixed": "1.2.15"
},
{
"introduced": "2.0.0"
},
{
"fixed": "2.0.2"
},
{
"introduced": "2.1.0"
},
{
"fixed": "2.1.2"
}
]
}