Directory traversal in Eclipse Mojarra before 2.3.14 allows attackers to read arbitrary files via the loc parameter or con parameter.
References
Link | Resource |
---|---|
https://bugs.eclipse.org/bugs/show_bug.cgi?id=550943 | Issue Tracking Vendor Advisory |
https://github.com/eclipse-ee4j/mojarra/commit/cefbb9447e7be560e59da2da6bd7cb93776f7741 | Patch Third Party Advisory |
https://github.com/eclipse-ee4j/mojarra/issues/4571 | Issue Tracking Third Party Advisory |
https://www.oracle.com/security-alerts/cpuapr2022.html | Patch Third Party Advisory |
https://www.oracle.com/security-alerts/cpujan2022.html | Patch Third Party Advisory |
https://www.oracle.com/security-alerts/cpuoct2021.html | Patch Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2021-06-02T15:49:48
Updated: 2022-04-19T23:23:12
Reserved: 2020-01-13T00:00:00
Link: CVE-2020-6950
JSON object: View
NVD Information
Status : Analyzed
Published: 2021-06-02T16:15:08.357
Modified: 2022-05-12T14:06:59.757
Link: CVE-2020-6950
JSON object: View
Redhat Information
No data.
CWE