Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wrxx-w58g-3gqp

Опубликовано: 05 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

In Eclipse Mojarra versions 2.3 and following, URL handing in DefaultFaceletFactory does not properly sanitize and/or block remote URLs, allowing an attacker to specify a URL to a remote Facelet which will be included and processed as part of the normal request, with the privileges of the target server. This could allow access to restricted files such as WEB-INF/web.xml or /etc/passwd.

In Eclipse Mojarra versions 2.3 and following, URL handing in DefaultFaceletFactory does not properly sanitize and/or block remote URLs, allowing an attacker to specify a URL to a remote Facelet which will be included and processed as part of the normal request, with the privileges of the target server. This could allow access to restricted files such as WEB-INF/web.xml or /etc/passwd.

EPSS

Процентиль: 28%
0.00349
Низкий

7.5 High

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 8.1
redhat
6 дней назад

In Eclipse Mojarra versions 2.3 and following, URL handing in `DefaultFaceletFactory` does not properly sanitize and/or block remote URLs, allowing an attacker to specify a URL to a remote Facelet which will be included and processed as part of the normal request, with the privileges of the target server. This could allow access to restricted files such as `WEB-INF/web.xml` or `/etc/passwd`.

CVSS3: 7.5
nvd
7 дней назад

In Eclipse Mojarra versions 2.3 and following, URL handing in `DefaultFaceletFactory` does not properly sanitize and/or block remote URLs, allowing an attacker to specify a URL to a remote Facelet which will be included and processed as part of the normal request, with the privileges of the target server. This could allow access to restricted files such as `WEB-INF/web.xml` or `/etc/passwd`.

CVSS3: 7.5
debian
7 дней назад

In Eclipse Mojarra versions 2.3 and following, URL handing in `Default ...

EPSS

Процентиль: 28%
0.00349
Низкий

7.5 High

CVSS3

Дефекты

CWE-22