CVE-2018-14667
KEVlargeUnauthenticated EL Injection RCE in Red Hat JBoss RichFaces 3.x
CISA: Red Hat JBoss RichFaces Framework Expression Language Injection Vulnerability
RichFaces 3.x through 3.3.4, Red Hat's legacy JavaServer Faces (JSF) component framework, is vulnerable to unauthenticated Expression Language (EL) injection (CWE-94) in the UserResource resource. A remote attacker sends crafted requests to UserResource (org.ajax4jsf.resource.UserResource$UriData), causing the framework to evaluate attacker-controlled EL built from chains of Java serialized objects. Successful exploitation results in arbitrary code execution with the privileges of the affected Java application server, with no authentication or user interaction required (CVSS 3.1: 9.8). Any application or product deploying RichFrames 3.x — including deployments in Red Hat's JBoss/Enterprise Linux ecosystem — is affected, and since RichFrames 3.x is end-of-life many installations remain unpatched. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2023-09-28, confirming exploitation in the wild, and EPSS places it in the 99th percentile with a 74.2% probability of exploitation within 30 days.
What to do: Prioritize remediation given the KEV listing: apply mitigations or updated packages per Red Hat's vendor instructions, or discontinue/replace RichFrames 3.x (end-of-life) where fixes are unavailable, per CISA's required action. Inventory Java web applications for RichFrames 3.x usage (org.ajax4jsf / a4j components), focusing on internet-facing servers, and restrict access to UserResource endpoints if code updates are not immediately possible.
| Red Hat JBoss RichFaces Framework | 3.x through 3.3.4 |
| Red Hat Enterprise Linux | installations shipping affected RichFrames 3.x components (3.x through 3.3.4); exact package applicability per Red Hat advisories |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resource. A remote, unauthenticated attacker could exploit this to execute arbitrary code using a chain of java serialized objects via org.ajax4jsf.resource.UserResource$UriData.
- Affected
- Red Hat JBoss RichFaces Framework
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- redhat
- Products
- richfaces, enterprise linux
- Weakness
- CWE-94
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H