java-jsf-viewstate-faces-deserialization.md (1599B)
1 --- 2 title: "Java JSF ViewState Deserialization" 3 section: "Web Pentesting" 4 sectionSlug: "pentesting-web" 5 sourcePath: "src/pentesting-web/deserialization/java-jsf-viewstate-.faces-deserialization.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/pentesting-web/deserialization/java-jsf-viewstate-.faces-deserialization.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # Java JSF ViewState Deserialization 14 15 JavaServer Faces (JSF) may store view state in the client through the `javax.faces.ViewState` parameter. If the application accepts an unauthenticated serialized state without effective integrity protection, a crafted object graph can reach gadget classes on the server's classpath and lead to code execution during deserialization. Exploitability depends on the JSF implementation, its state-saving configuration, cryptographic protection, and available gadgets.<sup>[[1]](#references)</sup> 16 17 The first reference explains the affected configurations and mitigations. The second walks through a practical assessment in which exposed configuration material enabled a protected ViewState to be reproduced.<sup>[[1]](#references)</sup><sup>[[2]](#references)</sup> 18 19 ## References 20 21 - [1] [Misconfigured JSF ViewStates can lead to severe RCE vulnerabilities](https://www.alphabot.com/security/blog/2017/java/Misconfigured-JSF-ViewStates-can-lead-to-severe-RCE-vulnerabilities.html) 22 - [2] [Arkham - Hack The Box writeup (0xRick)](https://0xrick.github.io/hack-the-box/arkham/)