RichFaces
cpe:2.3:a:redhat:richfaces:*:*:*:*:*:*:*
- >= 3.1.0, <= 3.3.3
- >= 3.1.0, <= 3.3.4
This vulnerability is being actively exploited in the wild.
A vulnerability exists in the RichFaces Framework versions 3.0 through 3.3.4, allowing for Expression Language (EL) injection via the UserResource resource. This issue enables remote, unauthenticated attackers to execute arbitrary code by exploiting a chain of Java serialized objects through org.ajax4jsf.resource.UserResource$UriData.
Exploitation of this vulnerability allows for unauthorized remote code execution on the server where the affected RichFaces version is deployed.
Users can apply the security update available through the Red Hat JBoss Network. It is recommended to back up the existing JBoss installation and to stop the JBoss server process before applying the update. After the update, the JBoss server should be restarted.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.