CVE-2019-10068
Kentico Xperience Deserialization of Untrusted Data Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
YesDecision
Descriptions
An issue was discovered in Kentico 12.0.x before 12.0.15, 11.0.x before 11.0.48, 10.0.x before 10.0.52, and 9.x versions. Due to a failure to validate security headers, it was possible for a specially crafted request to the staging service to bypass the initial authentication and proceed to deserialize user-controlled .NET object input. This deserialization then led to unauthenticated remote code execution on the server where the Kentico instance was hosted.
Se descubrió un problema en Kentico 12.0.x anterior a la versión 12.0.15, 11.0.x antes de 11.0.48, 10.0.x antes de 10.0.52 y versiones 9.x. Debido a un fallo al validar los encabezados de seguridad, fue posible que una solicitud especialmente diseñada para el servicio de preparación omitiera la autenticación inicial y procediera a deserializar la entrada de objetos .NET controlada por el usuario. Esta deserialización condujo a una ejecución remota de código no autenticada en el servidor donde estaba alojada la instancia de Kentico.
Kentico contains a failure to validate security headers. This deserialization can led to unauthenticated remote code execution.
CVSS Scores
SSVC
- Decision:Act
Timeline
- 2019-03-26 CVE Reserved
- 2019-03-26 CVE Published
- 2020-05-06 First Exploit
- 2022-03-25 Exploited in Wild
- 2022-04-15 KEV Due Date
- 2025-02-07 CVE Updated
- 2025-03-30 EPSS Updated
CWE
- CWE-502: Deserialization of Untrusted Data
CAPEC
References (4)
URL | Date | SRC |
---|---|---|
https://packetstorm.news/files/id/157588 | 2020-05-06 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://devnet.kentico.com/download/hotfixes#securityBugs-v12 | 2020-04-15 |