A vulnerability in JBoss RichFaces versions 3.1.0 through 3.3.4 allows unauthenticated remote attackers to inject arbitrary Expression Language (EL) expressions via a specially crafted path containing the /DATA/ substring. The vulnerability is triggered in the context of the org.richfaces.renderkit.html.Paint2DResource$ImageData object, enabling attackers to execute arbitrary Java code on the server.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This 28-file repository is a self-contained Docker/Tomcat CTF lab and operational Python exploit for RichFaces Paint2DResource CVE-2018-12533. The Java lab emits a captcha URL containing a RichFactors-encoded, zlib-compressed Java serialization stream. The Python PoC fetches that blob, locates exactly two length-framed serialized EL strings, replaces both while repairing Java TC_BLOCKDATA framing, recompresses/re-encodes the payload, and requests the modified resource. The vulnerable Paint2DResourceServlet decodes an attacker-controlled path segment, passes it to an unfiltered ObjectInputStream, retrieves a MethodExpression from ImageData -> StateHolderSaver -> TagMethodExpression -> MethodExpressionImpl, and evaluates the recovered EL during JPEG rendering. The exploit supports direct header writes and a three-request session-preserving EL-to-SpEL chain that executes Runtime.exec commands or reads local files, returning results in response headers. Source is primarily Java, with Python exploit and blob inspection utilities plus a Bash end-to-end verifier. Docker Compose deliberately binds the vulnerable service only to 127.0.0.1:8080 and runs it as unprivileged uid 1003 (labuser).
This repository provides a fully operational exploit for CVE-2018-12533 (RichFaces Paint2DResource remote code execution, also known as RF-14310). The exploit is implemented as a Python script ('paint2die.py') that automates the process of generating a malicious serialized Java object, packaging it into a JAR using Maven (via Docker), and sending the payload to a vulnerable RichFaces endpoint. The exploit supports both arbitrary command execution and reverse shell payloads, which can be specified via command-line arguments. The repository includes supporting Python modules for environment checks (Docker, SDKMAN), payload generation, and delivery, as well as the Java source code for the payload generator. The structure is modular, with clear separation between UI, core logic, and Java payload generation. The exploit targets RichFaces 3.3.x applications accessible over HTTP/S and requires the attacker to have Docker and SDKMAN installed locally. The main attack vector is network-based, exploiting a deserialization vulnerability in the Paint2DResource component to achieve remote code execution on the server.
This repository demonstrates and exploits CVE-2018-12533, a remote code execution vulnerability in JBoss RichFaces 3.3.4 (and possibly other 3.x versions). The exploit works by generating a malicious serialized Java object (Paint2DResource$ImageData) containing an Expression Language (EL) payload that is executed on the server. The main file, Generator_Paint2DResourceImageData.java, creates this payload, compresses and encodes it in a format expected by the vulnerable RichFaces endpoint. The README provides detailed instructions for generating, decoding, and sending the payload to the endpoint (e.g., /a4j/s/3_3_3.Finalorg.richfaces.renderkit.html.Paint2DResource/DATA/{payload}.seam). The repository also includes JavaObjectDeserializer.java for analyzing payloads, and example filter/valve code to mitigate the vulnerability by blocking requests to the vulnerable endpoint. The exploit is operational and allows arbitrary command execution on the target server, with the default payload creating a file as proof of execution. The attack vector is network-based, requiring HTTP access to the vulnerable endpoint.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.