Bugzilla will be upgraded to version 5.0 on a still to be determined date in the near future. The original upgrade date has been delayed.
Bug 760692 - (CVE-2011-4343) CVE-2011-4343 MyFaces 2: EL injection, includeViewParameters re-evaluates param/model values as EL expressions
CVE-2011-4343 MyFaces 2: EL injection, includeViewParameters re-evaluates par...
Status: CLOSED NOTABUG
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
high Severity high
: ---
: ---
Assigned To: Red Hat Product Security
impact=important,public=20111122,repo...
: Security
: 757982 (view as bug list)
Depends On:
Blocks: 760693
  Show dependency treegraph
 
Reported: 2011-12-06 14:17 EST by Vincent Danen
Modified: 2015-08-19 05:14 EDT (History)
2 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2011-12-06 23:37:02 EST
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Vincent Danen 2011-12-06 14:17:29 EST
It was reported [1],[2] that Apache MyFaces 2 would re-evaluate param/model values as EL expressions under certain conditions. If a submit outcome included both faces-redirect=true and includeViewParams=true (or faces-include-view-params=true), it would be possible to inject EL expressions directly into input fields mapped as view parameters.

This is fixed in upstream versions 2.0.11 and 2.1.5.  A patch [3] and reproducer [4] are available.

[1] http://java.net/jira/browse/JAVASERVERFACES-2247
[2] https://issues.apache.org/jira/browse/MYFACES-3405
[3] https://issues.apache.org/jira/secure/attachment/12504807/MYFACES-3405-1.patch
[4] http://www.jakobk.com/2011/11/jsf-value-expression-injection-vulnerability/
Comment 1 David Jorm 2011-12-06 23:37:02 EST
Statement:

Not vulnerable. This issue affects the MyFaces 2 package, which is not shipped with any Red Hat products.
Comment 2 David Jorm 2011-12-06 23:37:44 EST
*** Bug 757982 has been marked as a duplicate of this bug. ***

Note You need to log in before you can comment on or make changes to this bug.