RichFaces: Expression Language injection via UserResource allows for unauthenticated remote code execution
Published Nov 6, 2018 ·Due Oct 19, 2023
9.8
CRITICALCVSS 3.1
EPSS 74.20%
Description
The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resource. A remote, unauthenticated attacker could exploit this to execute arbitrary code using a chain of java serialized objects via org.ajax4jsf.resource.UserResource$UriData.
Affected products
- Vendor n/a Product RichFaces Defaultn/a
- Version affected 3.X through 3.3.4StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | RichFaces | n/a |
|
Configuration 2
- 5.0
- 6.0
No data.
JBoss Enterprise BRMS Platform 5.3
RichFaces
Fixed · RHSA-2018:3581
Red Hat JBoss EAP 5
RichFaces
Fixed · RHSA-2018:3518
Red Hat JBoss Enterprise Application Platform 5 for RHEL 5
richfaces-0:3.3.1-9.SP3_patch_03.ep5.el5
Fixed · RHSA-2018:3517
Red Hat JBoss Enterprise Application Platform 5 for RHEL 6
richfaces-0:3.3.1-6.SP3_patch_03.ep5.el6
Fixed · RHSA-2018:3517
Red Hat JBoss SOA Platform 5.3
RichFaces
Fixed · RHSA-2018:3519
JBoss Developer Studio 11
RichFaces
Out of support scope
Red Hat JBoss Operations Network 3
RichFaces
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| JBoss Enterprise BRMS Platform 5.3 | RichFaces | Fixed | RHSA-2018:3581 |
| Red Hat JBoss EAP 5 | RichFaces | Fixed | RHSA-2018:3518 |
| Red Hat JBoss Enterprise Application Platform 5 for RHEL 5 | richfaces-0:3.3.1-9.SP3_patch_03.ep5.el5 | Fixed | RHSA-2018:3517 |
| Red Hat JBoss Enterprise Application Platform 5 for RHEL 6 | richfaces-0:3.3.1-6.SP3_patch_03.ep5.el6 | Fixed | RHSA-2018:3517 |
| Red Hat JBoss SOA Platform 5.3 | RichFaces | Fixed | RHSA-2018:3519 |
| JBoss Developer Studio 11 | RichFaces | Out of support scope | n/a |
| Red Hat JBoss Operations Network 3 | RichFaces | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
1 other source (GHSA) ▾
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:H
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AV:N/AC:L/Au:N/C:P/I:P/A:P
Date Added
Sep 28, 2023
Patch Due
Oct 19, 2023
Required Action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
ActiveAutomatable
YesTechnical Impact
TotalDecision
n/aAssessed Feb 7, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 2, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (36 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 2, 2026 | 74.20% (0.74202) | 99.48th | v5 (v2026.06.15) |
| Jun 15, 2026 | 74.17% (0.74171) | 99.42th | v5 (v2026.06.15) |
| Nov 4, 2025 | 89.37% (0.89374) | 99.52th | v4 (v2025.03.14) |
| Apr 8, 2025 | 88.14% (0.88137) | 99.46th | v4 (v2025.03.14) |
| Apr 7, 2025 | 87.11% (0.87105) | 99.41th | v4 (v2025.03.14) |
| Apr 4, 2025 | 88.14% (0.88137) | 99.46th | v4 (v2025.03.14) |
| Apr 3, 2025 | 87.11% (0.87105) | 99.41th | v4 (v2025.03.14) |
| Mar 29, 2025 | 88.14% (0.88137) | 99.38th | v4 (v2025.03.14) |
| Mar 27, 2025 | 87.11% (0.87105) | 99.39th | v4 (v2025.03.14) |
| Mar 17, 2025 | 88.14% (0.88137) | 99.46th | v4 (v2025.03.14) |
| Jan 1, 2025 | 61.54% (0.61536) | 97.96th | v3 (v2023.03.01) |
| Dec 17, 2024 | 69.34% (0.69338) | 98.18th | v3 (v2023.03.01) |
| Nov 21, 2024 | 83.78% (0.83783) | 98.57th | v3 (v2023.03.01) |
| Oct 16, 2024 | 82.26% (0.82259) | 98.47th | v3 (v2023.03.01) |
| Aug 21, 2024 | 79.98% (0.79976) | 98.36th | v3 (v2023.03.01) |
| Jul 22, 2024 | 81.05% (0.81054) | 98.37th | v3 (v2023.03.01) |
| Jun 25, 2024 | 70.76% (0.70756) | 98.06th | v3 (v2023.03.01) |
| May 8, 2024 | 64.59% (0.64591) | 97.88th | v3 (v2023.03.01) |
| Apr 19, 2024 | 65.35% (0.65355) | 97.86th | v3 (v2023.03.01) |
| Mar 29, 2024 | 71.50% (0.71498) | 97.99th | v3 (v2023.03.01) |
| Feb 15, 2024 | 73.02% (0.73024) | 98.00th | v3 (v2023.03.01) |
| Oct 31, 2023 | 82.09% (0.82093) | 98.03th | v3 (v2023.03.01) |
| Oct 16, 2023 | 84.42% (0.84417) | 98.11th | v3 (v2023.03.01) |
| Sep 29, 2023 | 87.23% (0.87229) | 98.24th | v3 (v2023.03.01) |
| Jul 8, 2023 | 71.15% (0.71154) | 97.59th | v3 (v2023.03.01) |
| Jun 22, 2023 | 75.21% (0.75212) | 97.69th | v3 (v2023.03.01) |
| Jun 2, 2023 | 78.72% (0.78723) | 97.76th | v3 (v2023.03.01) |
| May 5, 2023 | 69.19% (0.69186) | 97.46th | v3 (v2023.03.01) |
| Apr 4, 2023 | 74.77% (0.74772) | 97.60th | v3 (v2023.03.01) |
| Mar 7, 2023 | 78.30% (0.78304) | 97.65th | v3 (v2023.03.01) |
| Mar 6, 2023 | 69.18% (0.69181) | 99.13th | v2 (v2022.01.01) |
| Feb 4, 2022 | 69.18% (0.69181) | 98.96th | v2 (v2022.01.01) |
| Feb 3, 2022 | 15.90% (0.15901) | 90.17th | v1 |
| Jan 6, 2022 | 15.90% (0.15901) | 90.06th | v1 |
| Sep 1, 2021 | 15.90% (0.15901) | 97.32th | v1 |
| Apr 14, 2021 | 15.90% (0.15901) | 0.00th | v1 |
References (16)
- http://packetstormsecurity.com/files/156663/Richsploit-RichFaces-Exploitation-Toolkit.html x_refsource_MISCThird Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2020/Mar/21 mailing-listx_refsource_FULLDISCMailing ListThird Party Advisory
- http://www.securitytracker.com/id/1042037 vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2018:3517 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/errata/RHSA-2018:3518 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/errata/RHSA-2018:3519 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/errata/RHSA-2018:3581 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/security/cve/CVE-2018-14667 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1639139 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14667 x_refsource_CONFIRMIssue TrackingVendor Advisory
- https://github.com/advisories/GHSA-j7mw-7crr-658v Advisory
- https://github.com/richfaces/richfaces/commit/1372eb716c1a215a5af124198f21bde33fafad06
- https://nvd.nist.gov/vuln/detail/CVE-2018-14667
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-14667 government-resourceUS Government Resource
- https://www.cve.org/CVERecord?id=CVE-2018-14667
Change history (0)
No recorded changes yet.