{"id":"CVE-2016-5019","details":"CoreResponseStateManager in Apache MyFaces Trinidad 1.0.0 through 1.0.13, 1.2.x before 1.2.15, 2.0.x before 2.0.2, and 2.1.x before 2.1.2 might allow attackers to conduct deserialization attacks via a crafted serialized view state string.","aliases":["GHSA-x7rc-4gqw-3q6q"],"modified":"2026-07-08T12:41:38.569603Z","published":"2016-10-03T18:59:04.970Z","references":[{"type":"WEB","url":"https://www.oracle.com/security-alerts/cpujan2020.html"},{"type":"WEB","url":"https://www.oracle.com/security-alerts/cpujul2020.html"},{"type":"ADVISORY","url":"http://mail-archives.apache.org/mod_mbox/myfaces-users/201609.mbox/%3CCAM1yOjYM%2BEW3mLUfX0pNAVLfUFRAw-Bhvkp3UE5%3DEQzR8Yxsfw%40mail.gmail.com%3E"},{"type":"ADVISORY","url":"http://packetstormsecurity.com/files/138920/Apache-MyFaces-Trinidad-Information-Disclosure.html"},{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/93236"},{"type":"ADVISORY","url":"http://www.securitytracker.com/id/1037633"},{"type":"ADVISORY","url":"https://issues.apache.org/jira/browse/TRINIDAD-2542"},{"type":"FIX","url":"http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html"},{"type":"FIX","url":"http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html"},{"type":"FIX","url":"http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html"},{"type":"FIX","url":"http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html"},{"type":"FIX","url":"http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html"},{"type":"FIX","url":"http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/apache/myfaces-trinidad","events":[{"introduced":"a77b10fc2fa5e4514598a8a68e2a2dc0c3220725"},{"fixed":"859ef660eb7362863208cfdc254b3a73f414dbe4"},{"introduced":"6c34686505c1f139cb0bdcb9ec6648684b47230d"},{"fixed":"38e019904dd58b1c45e62bb1cb7d2da58ef2ccb6"},{"introduced":"9018bde651e0cf6472cb8e7f57a49acf510dd002"},{"fixed":"cf028379cfc5a30e0159939e65e0c14374231985"},{"introduced":"d6098ac8a3c0c9180788119a73fae84bf666bfdd"},{"fixed":"1bf7628b1c3d719061a237b00736f625409ab86a"}],"database_specific":{"cpe":"cpe:2.3:a:apache:myfaces_trinidad:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"1.0.0"},{"fixed":"1.0.13"},{"introduced":"1.2.0"},{"fixed":"1.2.15"},{"introduced":"2.0.0"},{"fixed":"2.0.2"},{"introduced":"2.1.0"},{"fixed":"2.1.2"}],"source":"CPE_RANGE"}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-5019.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}