PatchSiren

PatchSiren cyber security CVE debrief

CVE-2018-14667 Red Hat CVE debrief

CVE-2018-14667 is a Red Hat JBoss RichFaces Framework expression language injection vulnerability that CISA has placed in the Known Exploited Vulnerabilities catalog. For defenders, the key takeaway is that this issue is considered actively exploited and should be treated as urgent remediation work, especially where RichFaces is still deployed in production or exposed to untrusted input.

Vendor
Red Hat
Product
JBoss RichFaces Framework
CVSS
CRITICAL 9.8
CISA KEV
Listed
Original CVE published
2023-09-28
Original CVE updated
2023-09-28
Advisory published
2023-09-28
Advisory updated
2023-09-28

Who should care

Security and application teams running or maintaining Red Hat JBoss RichFaces Framework deployments, especially legacy web applications, externally reachable systems, and environments that may still depend on unsupported or difficult-to-patch components.

Technical summary

The published record identifies the issue as an expression language injection vulnerability in Red Hat JBoss RichFaces Framework. CISA’s KEV entry marks it as a known exploited vulnerability and directs organizations to apply vendor mitigations or discontinue use of the product if mitigations are unavailable. No additional technical details were provided in the supplied source corpus.

Defensive priority

High. CISA added this CVE to the KEV catalog on 2023-09-28 and set a remediation due date of 2023-10-19, indicating an urgent need to mitigate or remove affected deployments.

Recommended defensive actions

  • Inventory all applications and services using Red Hat JBoss RichFaces Framework.
  • Apply vendor-recommended mitigations where available.
  • If mitigations are unavailable, discontinue use of the product as CISA directs.
  • Prioritize internet-facing and business-critical deployments first.
  • Validate whether any legacy applications still depend on RichFaces and plan replacement or retirement.
  • Monitor for suspicious activity around affected applications and review relevant logs and WAF protections.

Evidence notes

The source corpus includes the CISA KEV record for CVE-2018-14667, which names the vulnerability as a Red Hat JBoss RichFaces Framework Expression Language Injection Vulnerability and marks it as known exploited. The KEV metadata also states the required action: apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Official reference links supplied include the CVE record, NVD detail page, and the CISA KEV catalog.

Sources and references

Verified primary and authoritative sources

  • CVE-2018-14667 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2018-14667

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2018-14667 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2018-14667

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

  • CISA Known Exploited Vulnerabilities catalog

    Publisher, destination, and source semantics verified

    URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog

    Cybersecurity and Infrastructure Security Agency - Official CISA catalog of vulnerabilities known to be exploited in the wild.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json

    cisa_kev

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.