Bug 1192140 (CVE-2015-0279) - CVE-2015-0279 RichFaces: Remote Command Execution via insufficient EL parameter sanitization
Summary: CVE-2015-0279 RichFaces: Remote Command Execution via insufficient EL paramet...
Alias: CVE-2015-0279
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
Depends On: 1196771 1196772 1196773 1205373 1206018
Blocks: 1192141 1196328 1203795
TreeView+ depends on / blocked
Reported: 2015-02-12 16:52 UTC by Vasyl Kaigorodov
Modified: 2023-09-15 06:43 UTC (History)
44 users (show)

Fixed In Version: RichFaces 4.5.4
Doc Type: Bug Fix
Doc Text:
It was found that the 'do' parameter permitted expression language (EL) injection, which could allow a remote attacker to execute Java methods on an affected server.
Clone Of:
Last Closed: 2017-06-20 19:31:01 UTC

Attachments (Terms of Use)
patch commit diffs (1.81 KB, text/plain)
2015-03-24 14:58 UTC, Chess Hazlett
no flags Details

System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2015:0719 0 normal SHIPPED_LIVE Important: Red Hat JBoss Web Framework Kit 2.7.0 security update 2015-03-25 01:06:10 UTC

Description Vasyl Kaigorodov 2015-02-12 16:52:10 UTC
It was reported [1] that remote attackers can inject EL (Expression Language) via "do" parameter.
This leads to remote Java method execution vulnerability.

[1]: https://issues.jboss.org/browse/RF-13977

Comment 6 Chess Hazlett 2015-03-19 20:26:19 UTC

Red Hat would like to thank Takeshi Terada of Mitsui Bussan Secure Directions, Inc. for reporting this issue.

Comment 8 Chess Hazlett 2015-03-24 14:58:25 UTC
Created attachment 1005892 [details]
patch commit diffs

Comment 9 Tomas Hoger 2015-03-24 19:17:28 UTC
Created wildfly tracking bugs for this issue:

Affects: fedora-all [bug 1205373]

Comment 10 errata-xmlrpc 2015-03-24 21:08:08 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Web Framework Kit 2.7.0

Via RHSA-2015:0719 https://rhn.redhat.com/errata/RHSA-2015-0719.html

Comment 19 Martin Prpič 2015-04-21 09:37:02 UTC

This issue did not affect any version of Red Hat JBoss Enterprise Application Platform 5 as they did not include the vulnerable version of the RichFaces component. JBoss EAP 5.x includes versions 3.3.1.x of RichFaces; this vulnerability was introduced in version 4.x of RichFaces.

Note You need to log in before you can comment on or make changes to this bug.