CRITICAL9.8
GHSA-j239-4gqg-5j54
Inadequate Encryption Strength
Quick fix
GHSA-j239-4gqg-5j54 — org.primefaces:primefaces: upgrade to the fixed version with the command below.
# pom.xml: bump <version>6.0</version> for org.primefaces:primefacesDetails
Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution
Are you affected?
Enter the version of the package you're using.
Affected packages
Maven/org.primefaces:primefaces
Introduced in:
5.0Fixed in: 6.0Fix
# pom.xml: bump <version>6.0</version> for org.primefaces:primefacesReferences
- https://nvd.nist.gov/vuln/detail/CVE-2017-1000486[ADVISORY]
- https://github.com/primefaces/primefaces/issues/1152[WEB]
- https://cryptosense.com/weak-encryption-flaw-in-primefaces[WEB]
- https://www.exploit-db.com/exploits/43733[WEB]
- http://blog.mindedsecurity.com/2016/02/rce-in-oracle-netbeans-opensource.html[WEB]