CVE-2018-12532: Critical severity red hat richfaces vulnerability
Published Jun 18, 2018
·Updated
JBoss RichFaces 4.5.3 through 4.5.17 allows unauthenticated remote attackers to inject an arbitrary expression language (EL) variable mapper and execute arbitrary Java code via a MediaOutputResource's resource request, aka RF-14309.
Affected Software
1 affected component
redhat Richfaces>=4.5.3<=4.5.17
Event History
Jun 18, 2018
CVE Published
via MITRE·12:00 PM
Data Sourced
via MITRE·12:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-12532?
CVE-2018-12532 has been rated as a high severity vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2018-12532?
To mitigate CVE-2018-12532, upgrade JBoss RichFaces to version 4.5.18 or later.
3
Who is affected by CVE-2018-12532?
CVE-2018-12532 affects all versions of JBoss RichFaces from 4.5.3 to 4.5.17.
4
What type of attack is possible with CVE-2018-12532?
An unauthenticated remote attacker can exploit CVE-2018-12532 to inject arbitrary Expression Language variables and execute Java code.
5
When was CVE-2018-12532 published?
CVE-2018-12532 was published in April 2018.