CVE-2018-14667: Red Hat JBoss RichFaces Framework Expression Language Injection Vulnerability
Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2023-09-28. EPSS: 74.2% chance of exploitation in the next 30 days.
The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resource. A remote, unauthenticated attacker could exploit this to execute arbitrary code using a chain of java serialized objects via org.ajax4jsf.resource.UserResource$UriData.
Affected products
- Red Hat Enterprise Linux: version 5.0 only; version 6.0 only
- Red Hat RichFaces: from 3.1.0, up to and including 3.3.4
Published 2018-11-06. Last modified 2026-06-17.