VDB
CVE-2018-12533
CVE-2018-12533
PUBLISHED
CVSS 9.800000190734863 CRITICAL
JBoss RichFaces 3.1.0 through 3.3.4 allows unauthenticated remote attackers to inject expression language (EL) expressions and execute arbitrary Java code via a /DATA/ substring in a path with an org.richfaces.renderkit.html.Paint2DResource$ImageData object, aka RF-14310.
EPSS 19.04% · 97.2th percentile
Risk Scores
CVSS 3.0
9.800000190734863
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
19.04%
97.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Maven | org.richfaces:richfaces-core | 3.1.0 |
| n/a | n/a | n/a |
| redhat | richfaces | 3.1.0 |
Timeline
- Jun 18, 2018 CVE Published
- Apr 14, 2021 EPSS Score
- Feb 4, 2022 EPSS Score
- Mar 7, 2023 EPSS Score
- Aug 23, 2023 EPSS Score
- Nov 9, 2023 EPSS Score
- Dec 19, 2023 EPSS Score
- Sep 21, 2024 EPSS Score
- Nov 14, 2024 PoC Published
- Nov 21, 2024 CVE Updated
- Dec 17, 2024 EPSS Score
- Mar 17, 2025 EPSS Score
References
- RHSA-2018:2664 vendor-advisory
- 1041617 vdb
- 104502 vdb
- https://nvd.nist.gov/vuln/detail/CVE-2018-12533 advisory
- https://access.redhat.com/errata/RHSA-2018:2930 url
- https://codewhitesec.blogspot.com/2018/05/poor-richfaces.html url
- http://seclists.org/fulldisclosure/2020/Mar/21 technical
- https://access.redhat.com/errata/RHSA-2018:2663 advisory