Description
Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution
Remediation
References
https://github.com/primefaces/primefaces/issues/1152
https://cryptosense.com/weak-encryption-flaw-in-primefaces/
http://blog.mindedsecurity.com/2016/02/rce-in-oracle-netbeans-opensource.html
https://www.exploit-db.com/exploits/43733/
Related Vulnerabilities
CVE-2021-23424 Vulnerability in npm package ansi-html
CVE-2019-15138 Vulnerability in maven package org.webjars.npm:html-pdf
CVE-2020-8237 Vulnerability in npm package json-bigint
CVE-2021-23326 Vulnerability in npm package @graphql-tools/git-loader
CVE-2021-44550 Vulnerability in maven package edu.stanford.nlp:stanford-corenlp