The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resource. A remote, unauthenticated attacker could exploit this to execute arbitrary code using a chain of java serialized objects via org.ajax4jsf.resource.UserResource$UriData.
References
Configurations
History
No history.
Information
Published : 2018-11-06 22:29
Updated : 2025-01-27 21:56
NVD link : CVE-2018-14667
Mitre link : CVE-2018-14667
CVE.ORG link : CVE-2018-14667
JSON object : View
Products Affected
redhat
- richfaces
- enterprise_linux
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')