CVE-2011-4343
published 2017-08-08CVE-2011-4343: Information disclosure vulnerability in Apache MyFaces Core 2.0.1 through 2.0.10 and 2.1.0 through 2.1.4 allows remote attackers to inject EL expressions via…
PriorityP342high7.5CVSS 3.0
AVNACLPRNUINSUCHINAN
EPSS
5.33%
91.7th percentile
Information disclosure vulnerability in Apache MyFaces Core 2.0.1 through 2.0.10 and 2.1.0 through 2.1.4 allows remote attackers to inject EL expressions via crafted parameters.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | myfaces | — | — |
| apache | myfaces | — | — |
| apache | myfaces | — | — |
| apache | myfaces | — | — |
| apache | myfaces | — | — |
| apache | myfaces | — | — |
| apache | myfaces | — | — |
| apache | myfaces | — | — |
| apache | myfaces | — | — |
| apache | myfaces | — | — |
| apache | myfaces | — | — |
| apache | myfaces | — | — |
| apache | myfaces | — | — |
| apache | myfaces | — | — |
| apache | myfaces | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Apache MyFaces Vulnerable to EL Injection
ghsa·2022-05-17
CVE-2011-4343 [HIGH] CWE-200 Apache MyFaces Vulnerable to EL Injection
Apache MyFaces Vulnerable to EL Injection
Information disclosure vulnerability in Apache MyFaces Core 2.0.1 through 2.0.10 and 2.1.0 through 2.1.4 allows remote attackers to inject EL expressions via crafted parameters.
OSV
Apache MyFaces Vulnerable to EL Injection
osv·2022-05-17
CVE-2011-4343 [HIGH] Apache MyFaces Vulnerable to EL Injection
Apache MyFaces Vulnerable to EL Injection
Information disclosure vulnerability in Apache MyFaces Core 2.0.1 through 2.0.10 and 2.1.0 through 2.1.4 allows remote attackers to inject EL expressions via crafted parameters.
Red Hat
2: EL injection, includeViewParameters re-evaluates param/model values as EL expressions
vendor_redhat·2011-11-22·CVSS 7.5
CVE-2011-4343 [HIGH] 2: EL injection, includeViewParameters re-evaluates param/model values as EL expressions
2: EL injection, includeViewParameters re-evaluates param/model values as EL expressions
Information disclosure vulnerability in Apache MyFaces Core 2.0.1 through 2.0.10 and 2.1.0 through 2.1.4 allows remote attackers to inject EL expressions via crafted parameters.
Statement: Not vulnerable. This issue affects the MyFaces 2 package, which is not shipped with any Red Hat products.
Package: Other (Red Hat JBoss Enterprise Web Server 1) - Not affected
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-4343 MyFaces 2: EL injection, includeViewParameters re-evaluates param/model values as EL expressions
bugzilla·2011-12-06·CVSS 7.5
CVE-2011-4343 [HIGH] CVE-2011-4343 MyFaces 2: EL injection, includeViewParameters re-evaluates param/model values as EL expressions
CVE-2011-4343 MyFaces 2: EL injection, includeViewParameters re-evaluates param/model values as EL expressions
It was reported [1],[2] that Apache MyFaces 2 would re-evaluate param/model values as EL expressions under certain conditions. If a submit outcome included both faces-redirect=true and includeViewParams=true (or faces-include-view-params=true), it would be possible to inject EL expressions directly into input fields mapped as view parameters.
This is fixed in upstream versions 2.0.11 and 2.1.5. A patch [3] and reproducer [4] are available.
[1] http://java.net/jira/browse/JAVASERVERFACES-2247
[2] https://issues.apache.org/jira/browse/MYFACES-3405
[3] https://issues.apache.org/jira/secure/attachment/12504807/MYFACES-3405-1.patch
[4] http://www.jakobk.com/2011/11/jsf-value-express
Bugzilla
MyFaces 2 EL injection: includeViewParameters re-evaluates param/model values as EL expressions
bugzilla·2011-11-29·CVSS 7.5
[HIGH] MyFaces 2 EL injection: includeViewParameters re-evaluates param/model values as EL expressions
MyFaces 2 EL injection: includeViewParameters re-evaluates param/model values as EL expressions
MyFaces 2 will re-evaluate param/model values as EL expressions when
includeViewParameters is set to true. This flaw allows an attacker to inject EL
expressions.
External References:
https://issues.apache.org/jira/browse/MYFACES-3405
http://www.jakobk.com/2011/11/jsf-value-expression-injection-vulnerability/
Discussion:
Statement:
Not vulnerable. This issue affects the MyFaces 2 package, which is not
shipped with any Red Hat products.
---
*** This bug has been marked as a duplicate of bug 760692 ***
---
This CVE was rejected as a duplicate of CVE-2011-4343, so I'm removing the CVE references.
http://marc.info/?l=full-disclosure&m=132313252814362http://www.securitytracker.com/id/1039695https://issues.apache.org/jira/secure/attachment/12504807/MYFACES-3405-1.patchhttp://marc.info/?l=full-disclosure&m=132313252814362http://www.securitytracker.com/id/1039695https://issues.apache.org/jira/secure/attachment/12504807/MYFACES-3405-1.patch
2017-08-08
Published