CVE-2018-14667
CRITICAL KEVRichFaces Framework 3.X-3.3.4 - Code Injection
Title source: llmDescription
The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resource. A remote, unauthenticated attacker could exploit this to execute arbitrary code using a chain of java serialized objects via org.ajax4jsf.resource.UserResource$UriData.
Exploits (6)
nomisec
WORKING POC
50 stars
by syriusbughunt · client-side
https://github.com/syriusbughunt/CVE-2018-14667
References (9)
Scores
CVSS v3
9.8
EPSS
0.8946
EPSS Percentile
99.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CISA KEV
2023-09-28
VulnCheck KEV
2023-09-28
InTheWild.io
2023-09-28
ENISA EUVD
EUVD-2022-4307
CWE
CWE-94
Status
published
Products (4)
org.richfaces/richfaces-core
0 - 3.3.4Maven
redhat/enterprise_linux
5.0
redhat/enterprise_linux
6.0
redhat/richfaces
3.1.0 - 3.3.4
Published
Nov 06, 2018
KEV Added
Sep 28, 2023
Tracked Since
Feb 18, 2026