CVE-2018-12532
18.06.2018, 12:29
JBoss RichFaces 4.5.3 through 4.5.17 allows unauthenticated remote attackers to inject an arbitrary expression language (EL) variable mapper and execute arbitrary Java code via a MediaOutputResource's resource request, aka RF-14309.
Vendor | Product | Version |
---|---|---|
redhat | richfaces | 4.5.3 ≤ 𝑥 ≤ 4.5.17 |
𝑥
= Vulnerable software versions
References