CVE-2018-14667
קריטית 9.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Red Hat JBoss RichFaces Framework Expression Language Injection Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
תיאור (מקור, אנגלית)
The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resource. A remote, unauthenticated attacker could exploit this to execute arbitrary code using a chain of java serialized objects via org.ajax4jsf.resource.UserResource$UriData.
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 74% (אחוזון 100) נכון ל-25/7/2026
- CWE
- CWE-94
מוצרים מושפעים
redhat: richfaces; redhat: enterprise linux
קישורים
- https://access.redhat.com/errata/RHSA-2018:3517 Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:3518 Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:3519 Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:3581 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14667 Issue TrackingVendor Advisory
- https://access.redhat.com/errata/RHSA-2018:3517 Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:3518 Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:3519 Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:3581 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14667 Issue TrackingVendor Advisory