Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2011-4367

Опубликовано: 05 авг. 2020
Источник: redhat
CVSS3: 7.5

Описание

Multiple directory traversal vulnerabilities in MyFaces JavaServer Faces (JSF) in Apache MyFaces Core 2.0.x before 2.0.12 and 2.1.x before 2.1.6 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) ln parameter to faces/javax.faces.resource/web.xml or (2) the PATH_INFO to faces/javax.faces.resource/.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat BPM Suite 6MyFacesNot affected
Red Hat Decision Manager 7MyFacesNot affected
Red Hat JBoss Enterprise Application Platform 6MyFacesNot affected
Red Hat JBoss Enterprise Application Platform 7MyFacesNot affected
Red Hat JBoss Enterprise Application Platform Continuous DeliveryMyFacesNot affected
Red Hat JBoss Fuse 6MyFacesNot affected
Red Hat Process Automation 7MyFacesNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=1866260MyFaces: multiple directory traversal vulnerabilities allow remote attackers to read arbitrary files

7.5 High

CVSS3

Связанные уязвимости

nvd
больше 11 лет назад

Multiple directory traversal vulnerabilities in MyFaces JavaServer Faces (JSF) in Apache MyFaces Core 2.0.x before 2.0.12 and 2.1.x before 2.1.6 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) ln parameter to faces/javax.faces.resource/web.xml or (2) the PATH_INFO to faces/javax.faces.resource/.

debian
больше 11 лет назад

Multiple directory traversal vulnerabilities in MyFaces JavaServer Fac ...

github
больше 3 лет назад

Apache MyFaces Vulnerable to Path Traversal

7.5 High

CVSS3