First published: Mon Jun 18 2018(Updated: )
JBoss RichFaces 4.5.3 through 4.5.17 allows unauthenticated remote attackers to inject an arbitrary expression language (EL) variable mapper and execute arbitrary Java code via a MediaOutputResource's resource request, aka RF-14309.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat RichFaces | >=4.5.3<=4.5.17 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-12532 has been rated as a high severity vulnerability due to its potential for remote code execution.
To mitigate CVE-2018-12532, upgrade JBoss RichFaces to version 4.5.18 or later.
CVE-2018-12532 affects all versions of JBoss RichFaces from 4.5.3 to 4.5.17.
An unauthenticated remote attacker can exploit CVE-2018-12532 to inject arbitrary Expression Language variables and execute Java code.
CVE-2018-12532 was published in April 2018.