]
Jozef Hartinger commented on JBSEAM-4804:
-----------------------------------------
Verified on Seam 2.2.2.Final
JBoss Seam2 privilege escalation caused by EL interpolation in
FacesMessages
----------------------------------------------------------------------------
Key: JBSEAM-4804
URL:
https://issues.jboss.org/browse/JBSEAM-4804
Project: Seam 2
Issue Type: Bug
Components: Security
Affects Versions: 2.0.2.SP1, 2.2.1.Final
Reporter: Marek Novotny
Assignee: Marek Novotny
Priority: Blocker
Fix For: 2.2.2.Final
Seam 2 does not properly block access to EL constructs in page exception
handling. This allowed arbitrary Java methods to be executed. A remote attacker
could use this flaw to execute arbitrary code via a URL, containing appended,
specially-crafted expression language parameters, provided to certain
applications based on the JBoss Seam framework.
Note: A properly configured and enabled Java Security Manager would prevent
exploitation of this flaw.
Details are in
https://www.redhat.com/security/data/cve/CVE-2011-1484.html
Seam team thanks Martin Kouba from IT SYSTEMS a.s. for reporting this issue.
--
This message is automatically generated by JIRA.
For more information on JIRA, see: