RichFaces: Injection of arbitrary EL variable mapper allows to bypass mitigation of CVE-2015-0279 and thereby remote code execution
Published Jun 18, 2018
9.8
CRITICALCVSS 3.0
EPSS 7.05%
Description
JBoss RichFaces 4.5.3 through 4.5.17 allows unauthenticated remote attackers to inject an arbitrary expression language (EL) variable mapper and execute arbitrary Java code via a MediaOutputResource's resource request, aka RF-14309.
Affected products
No data.
No data.
JBoss Developer Studio 11
RichFaces
Not affected
Red Hat JBoss BRMS 5
RichFaces
Not affected
Red Hat JBoss Data Virtualization 6
RichFaces
Not affected
Red Hat JBoss Enterprise Application Platform 5
RichFaces
Not affected
Red Hat JBoss Enterprise Application Platform 6
RichFaces
Not affected
Red Hat JBoss Operations Network 3
RichFaces
Not affected
Red Hat JBoss SOA Platform 5
RichFaces
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| JBoss Developer Studio 11 | RichFaces | Not affected | n/a |
| Red Hat JBoss BRMS 5 | RichFaces | Not affected | n/a |
| Red Hat JBoss Data Virtualization 6 | RichFaces | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 5 | RichFaces | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | RichFaces | Not affected | n/a |
| Red Hat JBoss Operations Network 3 | RichFaces | Not affected | n/a |
| Red Hat JBoss SOA Platform 5 | RichFaces | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue does not affect the following Red Hat products, as they do not include the vulnerable version of the RichFaces component: Red Hat JBoss EAP 5.2 Red Hat JBoss Data Virtualization 6.4 Red Hat JBoss BRMS 5.3 Red Hat JBoss Operations Network 3.3
References (9)
- http://seclists.org/fulldisclosure/2020/Mar/21 mailing-listx_refsource_FULLDISC
- http://www.securityfocus.com/bid/104503 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- https://access.redhat.com/security/cve/CVE-2018-12532 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1584492 Issue Tracking
- https://codewhitesec.blogspot.com/2018/05/poor-richfaces.html x_refsource_MISCExploitThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-2197 Advisory
- https://github.com/advisories/GHSA-3hx6-fqpj-xfjr Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2018-12532
- https://www.cve.org/CVERecord?id=CVE-2018-12532
| Link | Providers | Tags |
|---|---|---|
| http://seclists.org/fulldisclosure/2020/Mar/21 | mailing-listx_refsource_FULLDISC | |
| http://www.securityfocus.com/bid/104503 | vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry | |
| https://access.redhat.com/security/cve/CVE-2018-12532 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1584492 | Issue Tracking | |
| https://codewhitesec.blogspot.com/2018/05/poor-richfaces.html | x_refsource_MISCExploitThird Party Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-2197 | Advisory | |
| https://github.com/advisories/GHSA-3hx6-fqpj-xfjr | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2018-12532 | ||
| https://www.cve.org/CVERecord?id=CVE-2018-12532 |
Change history (0)
No recorded changes yet.