CVE-2019-13116

The MuleSoft Mule Community Edition runtime engine before 3.8 allows remote attackers to execute arbitrary code because of Java Deserialization, related to Apache Commons Collections
Configurations

Configuration 1 (hide)

cpe:2.3:a:mulesoft:mule_runtime:*:*:*:*:*:*:*:*

History

21 Nov 2024, 04:24

Type Values Removed Values Added
References () https://docs.mulesoft.com/release-notes/mule-runtime/mule-3.8.0-release-notes - Release Notes () https://docs.mulesoft.com/release-notes/mule-runtime/mule-3.8.0-release-notes - Release Notes
References () https://threat.tevora.com/mulesoft-3-8-unauthenticated-rce/ - Exploit, Third Party Advisory () https://threat.tevora.com/mulesoft-3-8-unauthenticated-rce/ - Exploit, Third Party Advisory

Information

Published : 2019-10-16 20:15

Updated : 2024-11-21 04:24


NVD link : CVE-2019-13116

Mitre link : CVE-2019-13116

CVE.ORG link : CVE-2019-13116


JSON object : View

Products Affected

mulesoft

  • mule_runtime
CWE
CWE-502

Deserialization of Untrusted Data