Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q388-j7cw-ff7w

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью

Описание

Path Traversal in Eclipse Mojarra

Multiple path traversal flaws where found in Mojarra JSF2 implementation for identifying resources by name or from libraries. An unauthenticated remote attacker can use these flaws to gather otherwise undisclosed information from within an application's root.

Пакеты

Наименование

org.glassfish:javax.faces

maven
Затронутые версииВерсия исправления

>= 2.0.0, < 2.1.19

2.1.19

EPSS

Процентиль: 100%
0.91635
Критический

Дефекты

CWE-22

Связанные уязвимости

redhat
больше 12 лет назад

Unspecified vulnerability in the Oracle GlassFish Server component in Oracle Fusion Middleware 2.1.1, 3.0.1, and 3.1.2; the Oracle JDeveloper component in Oracle Fusion Middleware 11.1.2.3.0, 11.1.2.4.0, and 12.1.2.0.0; and the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6.0 and 12.1.1 allows remote attackers to affect confidentiality via unknown vectors related to Java Server Faces or Web Container.

nvd
больше 12 лет назад

Unspecified vulnerability in the Oracle GlassFish Server component in Oracle Fusion Middleware 2.1.1, 3.0.1, and 3.1.2; the Oracle JDeveloper component in Oracle Fusion Middleware 11.1.2.3.0, 11.1.2.4.0, and 12.1.2.0.0; and the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6.0 and 12.1.1 allows remote attackers to affect confidentiality via unknown vectors related to Java Server Faces or Web Container.

debian
больше 12 лет назад

Unspecified vulnerability in the Oracle GlassFish Server component in ...

EPSS

Процентиль: 100%
0.91635
Критический

Дефекты

CWE-22