ZeroHour

CVE-2018-14667

KEVlarge

Unauthenticated EL Injection RCE in Red Hat JBoss RichFaces 3.x

CISA: Red Hat JBoss RichFaces Framework Expression Language Injection Vulnerability

CVSS 3.1
9.8 critical
EPSS
74%p99
Published
()
KEV added
AI analysis

RichFaces 3.x through 3.3.4, Red Hat's legacy JavaServer Faces (JSF) component framework, is vulnerable to unauthenticated Expression Language (EL) injection (CWE-94) in the UserResource resource. A remote attacker sends crafted requests to UserResource (org.ajax4jsf.resource.UserResource$UriData), causing the framework to evaluate attacker-controlled EL built from chains of Java serialized objects. Successful exploitation results in arbitrary code execution with the privileges of the affected Java application server, with no authentication or user interaction required (CVSS 3.1: 9.8). Any application or product deploying RichFrames 3.x — including deployments in Red Hat's JBoss/Enterprise Linux ecosystem — is affected, and since RichFrames 3.x is end-of-life many installations remain unpatched. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2023-09-28, confirming exploitation in the wild, and EPSS places it in the 99th percentile with a 74.2% probability of exploitation within 30 days.

What to do: Prioritize remediation given the KEV listing: apply mitigations or updated packages per Red Hat's vendor instructions, or discontinue/replace RichFrames 3.x (end-of-life) where fixes are unavailable, per CISA's required action. Inventory Java web applications for RichFrames 3.x usage (org.ajax4jsf / a4j components), focusing on internet-facing servers, and restrict access to UserResource endpoints if code updates are not immediately possible.

Affected
Red Hat JBoss RichFaces Framework3.x through 3.3.4
Red Hat Enterprise Linuxinstallations shipping affected RichFrames 3.x components (3.x through 3.3.4); exact package applicability per Red Hat advisories
Estimated exposure
largetens of thousands of legacy Java application deployments worldwide (order-of-magnitude estimate) — RichFrames 3.x was widely bundled in JBoss/Java EE enterprise web applications in the late 2000s–2010s and persists in long-lived internal deployments, but no authoritative public install count or internet-exposed scan total exists, so…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resource. A remote, unauthenticated attacker could exploit this to execute arbitrary code using a chain of java serialized objects via org.ajax4jsf.resource.UserResource$UriData.

CISA Known Exploited Vulnerability
Affected
Red Hat JBoss RichFaces Framework
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
redhat
Products
richfaces, enterprise linux
Weakness
CWE-94
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news