CVE-2015-0279
published 2015-03-26CVE-2015-0279: JBoss RichFaces before 4.5.4 allows remote attackers to inject expression language (EL) expressions and execute arbitrary Java code via the do parameter.
PriorityP340medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
3.93%
89.1th percentile
JBoss RichFaces before 4.5.4 allows remote attackers to inject expression language (EL) expressions and execute arbitrary Java code via the do parameter.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | richfaces | 4.0.0 – 4.5.4 | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
RichFaces: Injection of arbitrary EL variable mapper allows to bypass mitigation of CVE-2015-0279 and thereby remote code execution
vendor_redhat·2018-05-30·CVSS 6.8
CVE-2018-12532 [MEDIUM] CWE-94 RichFaces: Injection of arbitrary EL variable mapper allows to bypass mitigation of CVE-2015-0279 and thereby remote code execution
RichFaces: Injection of arbitrary EL variable mapper allows to bypass mitigation of CVE-2015-0279 and thereby remote code execution
JBoss RichFaces 4.5.3 through 4.5.17 allows unauthenticated remote attackers to inject an arbitrary expression language (EL) variable mapper and execute arbitrary Java code via a MediaOutputResource's resource request, aka RF-14309.
Statement: This issue does not affect the following Red Hat products, as they do not include the vulnerable version of the RichFaces component:
Red Hat JBoss EAP 5.2
Red Hat JBoss Data Virtualization 6.4
Red Hat JBoss BRMS 5.3
Red Hat JBoss Operations Network 3.3
Package: RichFaces (JBoss Developer Studio 11) - Not affected
Package: RichFaces (Red Hat JBoss BRMS 5) - Not affected
Package: RichFaces (Red Hat JBoss Data Virtuali
Red Hat
RichFaces: Remote Command Execution via insufficient EL parameter sanitization
vendor_redhat·2015-03-24·CVSS 6.8
CVE-2015-0279 [MEDIUM] CWE-95 RichFaces: Remote Command Execution via insufficient EL parameter sanitization
RichFaces: Remote Command Execution via insufficient EL parameter sanitization
JBoss RichFaces before 4.5.4 allows remote attackers to inject expression language (EL) expressions and execute arbitrary Java code via the do parameter.
It was found that the 'do' parameter permitted expression language (EL) injection, which could allow a remote attacker to execute Java methods on an affected server.
Statement: This issue did not affect any version of Red Hat JBoss Enterprise Application Platform 5 as they did not include the vulnerable version of the RichFaces component. JBoss EAP 5.x includes versions 3.3.1.x of RichFaces; this vulnerability was introduced in version 4.x of RichFaces.
Package: wildfly (Red Hat JBoss Data Grid 6) - Not affected
Package: richfaces (Red Hat JBoss Enterprise
GHSA
GHSA-8cc3-p77g-5pcc: JBoss RichFaces before 4
ghsa_unreviewed·2022-05-14
CVE-2015-0279 [MEDIUM] CWE-94 GHSA-8cc3-p77g-5pcc: JBoss RichFaces before 4
JBoss RichFaces before 4.5.4 allows remote attackers to inject expression language (EL) expressions and execute arbitrary Java code via the do parameter.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-12532 RichFaces: Injection of arbitrary EL variable mapper allows to bypass mitigation of CVE-2015-0279 and thereby remote code execution
bugzilla·2018-05-31·CVSS 6.8
CVE-2018-12532 [MEDIUM] CVE-2018-12532 RichFaces: Injection of arbitrary EL variable mapper allows to bypass mitigation of CVE-2015-0279 and thereby remote code execution
CVE-2018-12532 RichFaces: Injection of arbitrary EL variable mapper allows to bypass mitigation of CVE-2015-0279 and thereby remote code execution
RichFaces version 4.5.3 ≤ 4.5.17 is vulnerable to injection of arbitrary EL variable mappers, allowing mitigation bypass of CVE-2015-0279 and thereby remote code execution.
External Reference:
https://codewhitesec.blogspot.com/2018/05/poor-richfaces.html
Discussion:
Upstream issue:
https://issues.jboss.org/browse/RF-14309
---
Statement:
This issue does not affect the following Red Hat products, as they do not include the vulnerable version of the RichFaces component:
Red Hat JBoss EAP 5.2
Red Hat JBoss Data Virtualization 6.4
Red Hat JBoss BRMS 5.3
Red Hat JBoss Operations Network 3.3
Bugzilla
CVE-2015-0279 wildfly: RichFaces: Remote Command Execution via insufficient EL parameter sanitization [fedora-all]
bugzilla·2015-03-24·CVSS 6.8
CVE-2015-0279 [MEDIUM] CVE-2015-0279 wildfly: RichFaces: Remote Command Execution via insufficient EL parameter sanitization [fedora-all]
CVE-2015-0279 wildfly: RichFaces: Remote Command Execution via insufficient EL parameter sanitization [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue af
Bugzilla
CVE-2015-0279 RichFaces: Remote Command Execution via insufficient EL parameter sanitization
bugzilla·2015-02-12·CVSS 6.8
CVE-2015-0279 [MEDIUM] CVE-2015-0279 RichFaces: Remote Command Execution via insufficient EL parameter sanitization
CVE-2015-0279 RichFaces: Remote Command Execution via insufficient EL parameter sanitization
It was reported [1] that remote attackers can inject EL (Expression Language) via "do" parameter.
This leads to remote Java method execution vulnerability.
[1]: https://issues.jboss.org/browse/RF-13977
Discussion:
Acknowledgements:
Red Hat would like to thank Takeshi Terada of Mitsui Bussan Secure Directions, Inc. for reporting this issue.
---
Created attachment 1005892
patch commit diffs
---
Created wildfly tracking bugs for this issue:
Affects: fedora-all [bug 1205373]
---
This issue has been addressed in the following products:
Red Hat JBoss Web Framework Kit 2.7.0
Via RHSA-2015:0719 https://rhn.redhat.com/errata/RHSA-2015-0719.html
---
Upstream commit:
https://github.com/richfa
http://jvn.jp/en/jp/JVN56297719/index.htmlhttp://jvndb.jvn.jp/en/contents/2015/JVNDB-2015-001959.htmlhttp://packetstormsecurity.com/files/153734/Tufin-Secure-Change-Remote-Code-Execution.htmlhttp://packetstormsecurity.com/files/156663/Richsploit-RichFaces-Exploitation-Toolkit.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0719.htmlhttp://seclists.org/fulldisclosure/2019/Jul/21http://seclists.org/fulldisclosure/2020/Mar/21https://bugzilla.redhat.com/show_bug.cgi?id=1192140http://jvn.jp/en/jp/JVN56297719/index.htmlhttp://jvndb.jvn.jp/en/contents/2015/JVNDB-2015-001959.htmlhttp://packetstormsecurity.com/files/153734/Tufin-Secure-Change-Remote-Code-Execution.htmlhttp://packetstormsecurity.com/files/156663/Richsploit-RichFaces-Exploitation-Toolkit.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0719.htmlhttp://seclists.org/fulldisclosure/2019/Jul/21http://seclists.org/fulldisclosure/2020/Mar/21https://bugzilla.redhat.com/show_bug.cgi?id=1192140
2015-03-26
Published