Bug 757982 - MyFaces 2 EL injection: includeViewParameters re-evaluates param/model values as EL expressions
Summary: MyFaces 2 EL injection: includeViewParameters re-evaluates param/model values...
Keywords:
Status: CLOSED DUPLICATE of bug 760692
Alias: None
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks: 757983
TreeView+ depends on / blocked
 
Reported: 2011-11-29 05:43 UTC by David Jorm
Modified: 2021-02-24 13:42 UTC (History)
3 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2011-11-29 06:11:04 UTC
Embargoed:


Attachments (Terms of Use)

Description David Jorm 2011-11-29 05:43:42 UTC
MyFaces 2 will re-evaluate param/model values as EL expressions when
includeViewParameters is set to true. This flaw allows an attacker to inject EL
expressions.

External References:
https://issues.apache.org/jira/browse/MYFACES-3405
http://www.jakobk.com/2011/11/jsf-value-expression-injection-vulnerability/

Comment 1 David Jorm 2011-11-29 06:11:04 UTC
Statement:

Not vulnerable. This issue affects the MyFaces 2 package, which is not
shipped with any Red Hat products.

Comment 2 David Jorm 2011-12-07 04:37:44 UTC

*** This bug has been marked as a duplicate of bug 760692 ***

Comment 3 Vincent Danen 2011-12-12 18:32:25 UTC
This CVE was rejected as a duplicate of CVE-2011-4343, so I'm removing the CVE references.


Note You need to log in before you can comment on or make changes to this bug.