Back

CRITICAL

RichFaces: Injection of arbitrary EL variable mapper allows to bypass mitigation of CVE-2015-0279 and thereby remote code execution

Published Jun 18, 2018

Description

JBoss RichFaces 4.5.3 through 4.5.17 allows unauthenticated remote attackers to inject an arbitrary expression language (EL) variable mapper and execute arbitrary Java code via a MediaOutputResource's resource request, aka RF-14309.

Affected products

Remediation

Red Hat statement

This issue does not affect the following Red Hat products, as they do not include the vulnerable version of the RichFaces component: Red Hat JBoss EAP 5.2 Red Hat JBoss Data Virtualization 6.4 Red Hat JBoss BRMS 5.3 Red Hat JBoss Operations Network 3.3

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jun 18, 2018
Updated Aug 5, 2024
Reserved Jun 18, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Critical
Public date May 30, 2018
ENISA EUVD
Assigner mitre
Published Jun 18, 2018
Updated Aug 5, 2024
Exploited since n/a
EUVD-2022-2197 GHSA-3HX6-FQPJ-XFJR