Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-66rg-hrjv-v265

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The PortletRequestDispatcher in PortletBridge, as used in Red Hat JBoss Portal 6.2.0, does not properly enforce the security constraints of servlets, which allows remote attackers to gain access to resources via a request that asks to render a non-JSF resource.

The PortletRequestDispatcher in PortletBridge, as used in Red Hat JBoss Portal 6.2.0, does not properly enforce the security constraints of servlets, which allows remote attackers to gain access to resources via a request that asks to render a non-JSF resource.

EPSS

Процентиль: 47%
0.00243
Низкий

Связанные уязвимости

redhat
больше 10 лет назад

The PortletRequestDispatcher in PortletBridge, as used in Red Hat JBoss Portal 6.2.0, does not properly enforce the security constraints of servlets, which allows remote attackers to gain access to resources via a request that asks to render a non-JSF resource.

nvd
больше 10 лет назад

The PortletRequestDispatcher in PortletBridge, as used in Red Hat JBoss Portal 6.2.0, does not properly enforce the security constraints of servlets, which allows remote attackers to gain access to resources via a request that asks to render a non-JSF resource.

EPSS

Процентиль: 47%
0.00243
Низкий