Back

CRITICAL

RichFaces: Injection of arbitrary EL expressions allows remote code execution via org.richfaces.renderkit.html.Paint2DResource

Published Jun 18, 2018

Description

JBoss RichFaces 3.1.0 through 3.3.4 allows unauthenticated remote attackers to inject expression language (EL) expressions and execute arbitrary Java code via a /DATA/ substring in a path with an org.richfaces.renderkit.html.Paint2DResource$ImageData object, aka RF-14310.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (12)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jun 18, 2018
Updated Aug 5, 2024
Reserved Jun 18, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Critical
Public date May 30, 2018
GHSA-4J38-WJHF-884R