CVE-2018-14667 is a critical Expression Language (EL) injection vulnerability affecting RichFaces Framework versions 3.X through 3.3.4, including Red Hat JBoss RichFaces. This flaw allows a remote, unauthenticated attacker to execute arbitrary code by exploiting the UserResource via a chain of Java serialized objects. With a CVSS score of 9.8 (Critical) and an EPSS score indicating high exploitability, it poses a significant risk due to its network-based attack vector and complete compromise potential (Confidentiality, Integrity, Availability). The vulnerability is actively exploited in the wild, as confirmed by its inclusion in CISA's KEV catalog and recent media coverage, despite a lack of public exploit modules on platforms like Metasploit or ExploitDB. Community discussion is notably high, reflecting widespread awareness and concern.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.1.0, <= 3.3.4CPE matchmatch criteria | cpe:2.3:a:redhat:richfaces:*:*:*:*:*:*:*:* | ||
5.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:5.0:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.