Skip to main content
All vulnerabilities
CVE-2018-14667

Red Hat JBoss RichFaces Framework Expression Language Injection Vulnerability

Red HatJBoss RichFaces Framework

Added to KEV catalog
28 September 2023
Federal remediation due date
19 October 2023
Weakness classification (CWE)
CWE-94

CISA Description

Red Hat JBoss RichFaces Framework contains an expression language injection vulnerability via the UserResource resource. A remote, unauthenticated attacker could exploit this vulnerability to execute malicious code using a chain of Java serialized objects via org.ajax4jsf.resource.UserResource$UriData.

Required action

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Notes

https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14667; https://nvd.nist.gov/vuln/detail/CVE-2018-14667

Confirm Your Exposure

Is this vulnerability present in your environment?

CRS delivers independent VAPT assessments that identify exactly which known-exploited vulnerabilities exist in your network, applications, and infrastructure.

Explore VAPT Services