CVE-2018-12533: Critical severity red hat richfaces vulnerability
JBoss RichFaces 3.1.0 through 3.3.4 allows unauthenticated remote attackers to inject expression language (EL) expressions and execute arbitrary Java code via a /DATA/ substring in a path with an org.richfaces.renderkit.html.Paint2DResource$ImageData object, aka RF-14310.
Other sources
RichFaces versions 3.x through 3.3.4 is vulnerable to injection of arbitrary EL expressions in org.richfaces.renderkit.html.Paint2DResource allowing remote attackers to execute arbitrary code.
External Reference:
https://codewhitesec.blogspot.com/2018/05/poor-richfaces.html
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-12533?
CVE-2018-12533 is classified as a high severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2018-12533?
To fix CVE-2018-12533, upgrade JBoss RichFaces to version 3.3.5 or later.
What types of systems are affected by CVE-2018-12533?
CVE-2018-12533 affects JBoss RichFaces versions 3.1.0 to 3.3.4.
Can CVE-2018-12533 be exploited remotely?
Yes, CVE-2018-12533 can be exploited by unauthenticated remote attackers.
What kind of attack is possible with CVE-2018-12533?
CVE-2018-12533 allows attackers to inject expression language (EL) expressions and execute arbitrary Java code.