Description
Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution
Remediation
References
http://blog.mindedsecurity.com/2016/02/rce-in-oracle-netbeans-opensource.html
https://cryptosense.com/weak-encryption-flaw-in-primefaces/
https://github.com/primefaces/primefaces/issues/1152
https://www.exploit-db.com/exploits/43733/
Related Vulnerabilities
CVE-2021-21310 Vulnerability in npm package next-auth
CVE-2020-10693 Vulnerability in maven package org.hibernate.validator:hibernate-validator
CVE-2022-4772 Vulnerability in maven package com.github.dgarijo:widoco
CVE-2022-23631 Vulnerability in npm package superjson
CVE-2022-22965 Vulnerability in maven package org.springframework:spring-webflux