4.5.17.Final
10 years ago
8 years ago
Known vulnerabilities in the org.richfaces:richfaces-a4j package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
org.richfaces:richfaces-a4j is an advanced UI component framework for easily integrating Ajax capabilities into business applications using JSF. Affected versions of this package are vulnerable to Arbitrary Code Execution. An attacker may be able to inject arbitrary EL variable mapper, thus bypassing the mitigation for CVE-2015-0279 Note: CVE-2018-12532 is a duplicate of CVE-2018-10848. How to fix Arbitrary Code Execution? There is no fix for | [0,) |
org.richfaces:richfaces-a4j is an advanced UI component framework for easily integrating Ajax capabilities into business applications using JSF. Affected versions of this package are vulnerable to Arbitrary Code Execution. Remote attackers may be able to inject expression language (EL) expressions and execute arbitrary Java code via the | [,4.5.4) |