First published: Thu May 31 2018(Updated: )
JBoss RichFaces 3.1.0 through 3.3.4 allows unauthenticated remote attackers to inject expression language (EL) expressions and execute arbitrary Java code via a /DATA/ substring in a path with an org.richfaces.renderkit.html.Paint2DResource$ImageData object, aka RF-14310.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat RichFaces | >=3.1.0<=3.3.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-12533 is classified as a high severity vulnerability due to its potential for remote code execution.
To fix CVE-2018-12533, upgrade JBoss RichFaces to version 3.3.5 or later.
CVE-2018-12533 affects JBoss RichFaces versions 3.1.0 to 3.3.4.
Yes, CVE-2018-12533 can be exploited by unauthenticated remote attackers.
CVE-2018-12533 allows attackers to inject expression language (EL) expressions and execute arbitrary Java code.