The US CISA has added the critical flaw CVE-2018-14667 with a CVSS score of 9.8 affecting Red Hat JBoss RichFaces Framework to its Known Exploited Vulnerabilities Catalog.
The issue is an Expression Language (EL) injection via the UserResource resource. It affects RichFaces Framework 3.X through 3.3.4. A remote, unauthenticated attacker could exploit this vulnerability to execute arbitrary code using a chain of java serialized objects via org.ajax4jsf.resource.UserResource$UriData.
The vulnerability was discovered by the security researcher Joao Filho Matos Figueiredo.
Experts recommend also private organizations review the Catalog and address the vulnerabilities in their infrastructure.
CISA orders federal agencies to fix this flaw by October 19, 2023.