Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-14667

Опубликовано: 06 нояб. 2018
Источник: redhat
CVSS3: 9.8
EPSS Высокий

Описание

The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resource. A remote, unauthenticated attacker could exploit this to execute arbitrary code using a chain of java serialized objects via org.ajax4jsf.resource.UserResource$UriData.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
JBoss Developer Studio 11RichFacesOut of support scope
Red Hat JBoss Operations Network 3RichFacesNot affected
JBoss Enterprise BRMS Platform 5.3RichFacesFixedRHSA-2018:358113.11.2018
Red Hat JBoss EAP 5RichFacesFixedRHSA-2018:351806.11.2018
Red Hat JBoss Enterprise Application Platform 5 for RHEL 5richfacesFixedRHSA-2018:351706.11.2018
Red Hat JBoss Enterprise Application Platform 5 for RHEL 6richfacesFixedRHSA-2018:351706.11.2018
Red Hat JBoss SOA Platform 5.3RichFacesFixedRHSA-2018:351907.11.2018

Показывать по

Дополнительная информация

Статус:

Critical
Дефект:
CWE-94
https://bugzilla.redhat.com/show_bug.cgi?id=1639139RichFaces: Expression Language injection via UserResource allows for unauthenticated remote code execution

EPSS

Процентиль: 100%
0.89374
Высокий

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
nvd
больше 7 лет назад

The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resource. A remote, unauthenticated attacker could exploit this to execute arbitrary code using a chain of java serialized objects via org.ajax4jsf.resource.UserResource$UriData.

CVSS3: 9.8
github
больше 3 лет назад

Richfaces vulnerable to arbitrary code execution

EPSS

Процентиль: 100%
0.89374
Высокий

9.8 Critical

CVSS3