The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resource. A remote, unauthenticated attacker could exploit this to execute arbitrary code using a chain of java serialized objects via org.ajax4jsf.resource.UserResource$UriData.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HRed Hat Enterprise Linux
OSRedhat5.06.0Red Hat Richfaces
APPRedhat3.1.0 – 3.3.4
CISA KEV — detailsi
- Vendori
- Red Hat ↗
- Producti
- JBoss RichFaces Framework
- Added to KEVi
- September 28, 2023
- Remediation deadline (US Federal)i
- October 19, 2023(overdue)
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Red Hat JBoss RichFaces Framework contains an expression language injection vulnerability via the UserResource resource. A remote, unauthenticated attacker could exploit this vulnerability to execute malicious code using a chain of Java serialized objects via org.ajax4jsf.resource.UserResource$UriData.
Related vulnerabilities
Sudo: eskalacja uprawnień do root poprzez opcję --chroot (CVE-2025-32463)
SSRF w mod_proxy Apache HTTP Server — przekierowanie żądań przez atakującego
GNU Bash — niekompletna łatka Shellshock umożliwia command injection (CVE-2014-7169)
ShellShock — RCE poprzez zmienne środowiskowe w GNU Bash
Apache Struts 2: RCE przez prefiks action/redirect w parametrach