CISA adds JBoss RichFaces Framework flaw to its Known Exploited Vulnerabilities catalog
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2018-14667 | Unauthenticated EL Injection RCE in Red Hat JBoss RichFaces 3.x RichFaces 3.x through 3.3.4, Red Hat's legacy JavaServer Faces (JSF) component framework, is vulnerable to unauthenticated Expression Language (EL) injection (CWE-94) in the UserResource resource. A remote attacker sends crafted requests to UserResource (org.ajax4jsf.resource.UserResource$UriData), causing the framework to evaluate attacker-controlled EL built from chains of Java serialized objects. Successful exploitation results in arbitrary code execution with the privileges of the affected Java application server, with no authentication or user interaction required (CVSS 3.1: 9.8). Any application or product deploying RichFrames 3.x — including deployments in Red Hat's JBoss/Enterprise Linux ecosystem — is affected, and since RichFrames 3.x is end-of-life many installations remain unpatched. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2023-09-28, confirming exploitation in the wild, and EPSS places it in the 99th percentile with a 74.2% probability of exploitation within 30 days. Do: Prioritize remediation given the KEV listing: apply mitigations or updated packages per Red Hat's vendor instructions, or discontinue/replace RichFrames 3.x (end-of-life) where fixes are unavailable, per CISA's required action. Inventory Java web applications for RichFrames 3.x usage (org.ajax4jsf / a4j components), focusing on internet-facing servers, and restrict access to UserResource endpoints if code updates are not immediately possible. | 9.8 | 74% | KEV |
| largetens of thousands of legacy Java application deployments worldwide (order-of-magnitude estimate) |
Full article191 words · extracted from securityaffairs.com · click to collapse
Pierluigi Paganini
September 29, 2023

US CISA added the flaw CVE-2018-14667 in Red Hat JBoss RichFaces Framework to its Known Exploited Vulnerabilities catalog.
US Cybersecurity and Infrastructure Security Agency (CISA) added the critical flaw CVE-2018-14667 (CVSS score 9.8) affecting Red Hat JBoss RichFaces Framework to its Known Exploited Vulnerabilities Catalog.
The issue is an Expression Language (EL) injection via the UserResource resource, it affects RichFaces Framework 3.X through 3.3.4. A remote, unauthenticated attacker could exploit this vulnerability to execute arbitrary code using a chain of java serialized objects via org.ajax4jsf.resource.UserResource$UriData.
The vulnerability was discovered by the security researcher Joao Filho Matos Figueiredo.
According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.
Experts recommend also private organizations review the Catalog and address the vulnerabilities in their infrastructure.
CISA orders federal agencies to fix this flaw by October 19, 2023.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, CISA Known Exploited Vulnerabilities catalog)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/151656/security/cisa-jboss-richfaces-framework-flaw-known-exploited-vulnerabilities-catalog.html