CVE-2018-14667 KEV
9.8
CRITICAL · CVSS 3.1 · EPSS 74.2% (pctl 99)
Patch first
On CISA KEV — known exploited in the wild, due 2023-10-19.
Description
The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resource. A remote, unauthenticated attacker could exploit this to execute arbitrary code using a chain of java serialized objects via org.ajax4jsf.resource.UserResource$UriData.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 74.2% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-94 |
| On CISA KEV | yes — remediate by 2023-10-19 |
| Public exploit | none known |
| Published | 2018-11-06 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | Red Hat JBoss RichFaces Framework Expression Language Injection Vulnerability |
|---|---|
| Added | 2023-09-28 |
| Due | 2023-10-19 |
| Vendor / product | Red Hat / JBoss RichFaces Framework |
| Ransomware use | none reported |
Affected (2)
| Vendor | Product |
|---|---|
| redhat | enterprise linux |
| redhat | richfaces |
References
- http://packetstormsecurity.com/files/156663/Richsploit-RichFaces-Exploitation-Toolkit.html
- http://seclists.org/fulldisclosure/2020/Mar/21
- http://www.securitytracker.com/id/1042037
- https://access.redhat.com/errata/RHSA-2018:3517
- https://access.redhat.com/errata/RHSA-2018:3518
- https://access.redhat.com/errata/RHSA-2018:3519
- https://access.redhat.com/errata/RHSA-2018:3581
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14667
- http://packetstormsecurity.com/files/156663/Richsploit-RichFaces-Exploitation-Toolkit.html
- http://seclists.org/fulldisclosure/2020/Mar/21
- http://www.securitytracker.com/id/1042037
- https://access.redhat.com/errata/RHSA-2018:3517
- https://access.redhat.com/errata/RHSA-2018:3518
- https://access.redhat.com/errata/RHSA-2018:3519
- https://access.redhat.com/errata/RHSA-2018:3581
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14667
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-14667
→ the Explorer · watch your stack · NVD