Update JSF to version 2.2.16

Assignee

Reporter

Sprint

Description

Vulnerability: CVE-2021-29995: Cross site request forgery (CSRF) leading to Remote Code Execution on the CloverDX Server

The cross site request forgery vulnerability exists in the recent version of CloverDX Server on all GUI based endpoints (JSF). The malicious attacker can use that vulnerability to perform any actions that is allowed through the GUI endpoint. One of the features of CloverDX Server is to create manual task execution –execute shell commands which the attacker can use to achieve remote code executionon the machine itself.

Fix

Fixed in JSF 2.2.16 by the following commit:

Bug 27445260: https://github.com/javaee/mojarra/commit/55afe42437facad5274f609f47761755e5b64bf0

Previously used version of JSF: 2.2.15

Credit

Thanks to Patryk Bogusz for reporting the issue.

Steps to reproduce

None

Activity

Fixed
Created March 16, 2021 at 9:50 AM
Updated September 12, 2023 at 8:44 AM
Resolved March 18, 2021 at 11:06 AM