Executive brief
Red Hat JBoss RichFaces Framework contains an Expression Language (EL) injection vulnerability in the UserResource component. A remote, unauthenticated attacker can exploit this by sending a chain of Java serialized objects via org.ajax4jsf.resource.UserResource$UriData to execute arbitrary code.
Affected products
- Red Hat RichFaces Framework 3.1.0 through 3.3.4
Timeline
- 2018-11-06: advisory: Red Hat issued security advisories (RHSA-2018:3517, RHSA-2018:3518, RHSA-2018:3519)
- 2023-09-28: kev added: Added to CISA Known Exploited Vulnerabilities Catalog