JBossÔ¶³Ì´úÂëÖ´Ðзì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2018-11-09

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2018-14667 £¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ 9.8 £¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


RichFaces Framework 3.Xµ½3.3.4


·ì϶¸ÅÊö


RichFaces Framework 3.Xµ½3.3.4ºÜÈÝÒ×ͨ¹ýUserResource×ÊÔ´×¢Èë±í°×ʽ˵»°£¨EL£©¡£ Ô¶³Ìδ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÄܹ»Í¨¹ýorg.ajax4jsf.resource.UserResource $ UriDataʹÓÃһϵÁÐjavaÐòÁл¯¶ÔÏóÀ´ÀûÓÃËüÀ´Ö´ÐÐËÁÒâ´úÂë¡£


·ì϶ÑéÖ¤


ÔÝÎÞPOC/EXP


½¨¸´½¨Òé


.RedHat¹Ù·½ÒѾ­°ä²¼ÁËа汾½¨¸´Á˸÷ì϶ £¬ÇëÊÜÓ°ÏìµÄÓû§ÊµÊ±¸üа汾 £¬ÐγɶԴ˷ì϶³Ö¾ÃÓÐЧµÄ·À»¤¡£
https://access.redhat.com/errata/RHSA-2018:3517

https://access.redhat.com/errata/RHSA-2018:3518


²Î¿¼Á´½Ó


https://securitytracker.com/id/1042037