JBossÔ¶³Ì´úÂëÖ´ÐÐÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2018-11-09

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2018-14667£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ 9.8£¬£¬£¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


RichFaces Framework 3.Xµ½3.3.4


Îó²î¸ÅÊö


RichFaces Framework 3.Xµ½3.3.4ºÜÈÝÒ×ͨ¹ýUserResource×ÊÔ´×¢Èë±í´ïʽÓïÑÔ£¨EL£© ¡£¡£¡£¡£¡£¡£¡£ Ô¶³Ìδ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔͨ¹ýorg.ajax4jsf.resource.UserResource $ UriDataʹÓÃһϵÁÐjavaÐòÁл¯¹¤¾ßÀ´Ê¹ÓÃËüÀ´Ö´ÐÐí§Òâ´úÂë ¡£¡£¡£¡£¡£¡£¡£


Îó²îÑéÖ¤


ÔÝÎÞPOC/EXP


ÐÞ¸´½¨Òé


.RedHat¹Ù·½ÒѾ­Ðû²¼ÁËа汾ÐÞ¸´Á˸ÃÎó²î£¬£¬£¬ÇëÊÜÓ°ÏìµÄÓû§ÊµÊ±¸üа汾£¬£¬£¬ÐγɶԴËÎó²îºã¾ÃÓÐÓõķÀ»¤ ¡£¡£¡£¡£¡£¡£¡£
https://access.redhat.com/errata/RHSA-2018:3517

https://access.redhat.com/errata/RHSA-2018:3518


²Î¿¼Á´½Ó


https://securitytracker.com/id/1042037