The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resource. A remote, unauthenticated attacker could exploit this to execute arbitrary code using a chain of java serialized objects via org.ajax4jsf.resource.UserResource$UriData.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: redhat

Published: 2018-11-06T22:00:00

Updated: 2020-03-14T00:06:01

Reserved: 2018-07-27T00:00:00


Link: CVE-2018-14667

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2018-11-06T22:29:00.193

Modified: 2020-08-28T17:59:25.087


Link: CVE-2018-14667

JSON object: View

cve-icon Redhat Information

No data.

CWE