CVE-2018-14667
Red Hat JBoss RichFaces Framework Expression Language Injection Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 19 October 2023). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resource. A remote, unauthenticated attacker could exploit this to execute arbitrary code using a chain of java serialized objects via org.ajax4jsf.resource.UserResource$UriData.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 74.17% probability · 99th percentile
- CISA KEV
- Listed 28 September 2023 · due 19 October 2023
- Weakness
- CWE-94
- Affected
- redhat/richfaces · redhat/enterprise linux
- Source
- secalert@redhat.com
CISA notes
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14667; https://nvd.nist.gov/vuln/detail/CVE-2018-14667
References
- http://packetstormsecurity.com/files/156663/Richsploit-RichFaces-Exploitation-Toolkit.htmlThird Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2020/Mar/21Mailing List, Third Party Advisory
- http://www.securitytracker.com/id/1042037Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2018:3517Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:3518Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:3519Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:3581Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14667Issue Tracking, Vendor Advisory
- http://packetstormsecurity.com/files/156663/Richsploit-RichFaces-Exploitation-Toolkit.htmlThird Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2020/Mar/21Mailing List, Third Party Advisory
- http://www.securitytracker.com/id/1042037Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2018:3517Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:3518Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:3519Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:3581Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14667Issue Tracking, Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-14667US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.