Bugzilla will be upgraded to version 5.0 on a still to be determined date in the near future. The original upgrade date has been delayed.
Bug 757980 - (CVE-2011-4358) CVE-2011-4358 Mojarra 2 EL injection: includeViewParameters re-evaluates param/model values as EL expressions
CVE-2011-4358 Mojarra 2 EL injection: includeViewParameters re-evaluates para...
Status: CLOSED NOTABUG
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
high Severity high
: ---
: ---
Assigned To: Red Hat Product Security
impact=important,public=20111117,repo...
: Security
Depends On:
Blocks: 757983
  Show dependency treegraph
 
Reported: 2011-11-29 00:37 EST by David Jorm
Modified: 2018-02-15 01:26 EST (History)
14 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2011-11-29 18:39:01 EST
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description David Jorm 2011-11-29 00:37:47 EST
Mojarra 2 will re-evaluate param/model values as EL expressions when includeViewParameters is set to true. This flaw allows an attacker to inject EL expressions.

External References:

http://java.net/jira/browse/JAVASERVERFACES-2247
http://www.jakobk.com/2011/11/jsf-value-expression-injection-vulnerability/
Comment 1 David Jorm 2011-11-29 18:39:01 EST
Statement:

Not vulnerable. This issue affects the Mojarra 2 package, which is not
shipped with any Red Hat products.
Comment 2 Jason Shepherd 2018-02-15 01:26:09 EST
I tested Wildfly Swarm (7.0.0.redhat-8) using the testcase from upstream and found it's not affected.

   https://github.com/jboss/mojarra/tree/svn/tags/2.1.5/jsf-test/JAVASERVERFACES-2247

Note You need to log in before you can comment on or make changes to this bug.