Junglewise Threat Intelligence

CVE-2018-14667: Richfaces vulnerable to arbitrary code execution

CVE-2018-14667 · Severity: critical · CVSS 3.1 · Exploited in the wild · Published 2022-05-13

Technologies: org.richfaces:richfaces-core (Maven). Vendors: Red Hat, Red Hat, Maven.

Executive brief

Red Hat JBoss RichFaces Framework contains an Expression Language (EL) injection vulnerability in the UserResource component. A remote, unauthenticated attacker can exploit this by sending a chain of Java serialized objects via org.ajax4jsf.resource.UserResource$UriData to execute arbitrary code.

Affected products

  • Red Hat RichFaces Framework 3.1.0 through 3.3.4

Timeline

  • 2018-11-06: advisory: Red Hat issued security advisories (RHSA-2018:3517, RHSA-2018:3518, RHSA-2018:3519)
  • 2023-09-28: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats