VDB
Sign up
CRITICAL9.8

GHSA-j7mw-7crr-658v

Richfaces vulnerable to arbitrary code execution

Quick fix

GHSA-j7mw-7crr-658v — org.richfaces:richfaces-core: upgrade to the fixed version with the command below.

# pom.xml: bump <version>3.3.4</version> for org.richfaces:richfaces-core

Details

The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resource. A remote, unauthenticated attacker could exploit this to execute arbitrary code using a chain of java serialized objects via `org.ajax4jsf.resource.UserResource$UriData`.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/org.richfaces:richfaces-core
Introduced in: 0Fixed in: 3.3.4
Fix# pom.xml: bump <version>3.3.4</version> for org.richfaces:richfaces-core

References