Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-6950

Опубликовано: 20 фев. 2020
Источник: redhat
CVSS3: 6.5

Описание

Directory traversal in Eclipse Mojarra before 2.3.14 allows attackers to read arbitrary files via the loc parameter or con parameter.

A flaw was found in Eclipse Mojarra before version 2.3.14, where it is vulnerable to a path traversal flaw via the loc parameter or the con parameter. An attacker could exploit this flaw to read arbitrary files.

Меры по смягчению последствий

There is no currently known mitigation for this flaw.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Decision Manager 7jsf-implNot affected
Red Hat JBoss Enterprise Application Platform 6jsf-implOut of support scope
Red Hat JBoss Fuse 6jsf-implOut of support scope
Red Hat JBoss Fuse Service Works 6jsf-implOut of support scope
Red Hat JBoss Operations Network 3jsf-implOut of support scope
Red Hat OpenShift Application Runtimesjsf-implAffected
Red Hat Process Automation 7jsf-implNot affected
Red Hat Satellite 5glassfish-jsf-implOut of support scope
EAP-CD 20 Tech Previewjsf-implFixedRHSA-2020:358531.08.2020
Red Hat Fuse 7.9jsf-implFixedRHSA-2021:314011.08.2021

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=1805006Mojarra: Path traversal via either the loc parameter or the con parameter, incomplete fix of CVE-2018-14371

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 5 лет назад

Directory traversal in Eclipse Mojarra before 2.3.14 allows attackers to read arbitrary files via the loc parameter or con parameter.

CVSS3: 6.5
nvd
больше 5 лет назад

Directory traversal in Eclipse Mojarra before 2.3.14 allows attackers to read arbitrary files via the loc parameter or con parameter.

CVSS3: 6.5
debian
больше 5 лет назад

Directory traversal in Eclipse Mojarra before 2.3.14 allows attackers ...

CVSS3: 7.5
github
около 5 лет назад

Directory traversal in Eclipse Mojarra

CVSS3: 7.5
fstec
больше 6 лет назад

Уязвимость компонента Web Container (JavaServer Faces) сервера приложений Oracle WebLogic Server, позволяющая нарушителю раскрыть защищаемую информацию

6.5 Medium

CVSS3