Back

CRITICAL KEV

RichFaces: Expression Language injection via UserResource allows for unauthenticated remote code execution

Published Nov 6, 2018 ·Due Oct 19, 2023

Description

The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resource. A remote, unauthenticated attacker could exploit this to execute arbitrary code using a chain of java serialized objects via org.ajax4jsf.resource.UserResource$UriData.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (16)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Nov 6, 2018
Updated Oct 21, 2025
Reserved Jul 27, 2018
CISA Vulnrichment
Updated Feb 7, 2025
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Critical
Public date Nov 6, 2018
GHSA-J7MW-7CRR-658V