JBossÔ¶³Ì´úÂëÖ´Ðзì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2018-11-09

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2018-14667£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ 9.8£¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


RichFaces Framework 3.Xµ½3.3.4


·ì϶¸ÅÊö


RichFaces Framework 3.Xµ½3.3.4ºÜÈÝÒ×ͨ¹ýUserResource×ÊÔ´×¢Èë±í°×ʽ˵»°£¨EL£© ¡£ Ô¶³Ìδ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÄܹ»Í¨¹ýorg.ajax4jsf.resource.UserResource $ UriDataʹÓÃһϵÁÐjavaÐòÁл¯¶ÔÏóÀ´ÀûÓÃËüÀ´Ö´ÐÐËÁÒâ´úÂë ¡£


·ì϶ÑéÖ¤


ÔÝÎÞPOC/EXP


½¨¸´½¨Òé


.RedHat¹Ù·½ÒѾ­°ä²¼ÁËа汾½¨¸´Á˸÷ì϶£¬ÇëÊÜÓ°ÏìµÄÓû§ÊµÊ±¸üа汾£¬ÐγɶԴ˷ì϶³Ö¾ÃÓÐЧµÄ·À»¤ ¡£
https://access.redhat.com/errata/RHSA-2018:3517

https://access.redhat.com/errata/RHSA-2018:3518


²Î¿¼Á´½Ó


https://securitytracker.com/id/1042037