Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: GSA_kwCzR0hTQS1xMzg4LWo3Y3ctZmY3d84AAcSt
Path Traversal in Eclipse Mojarra
Multiple path traversal flaws where found in Mojarra JSF2 implementation for identifying resources by name or from libraries. An unauthenticated remote attacker can use these flaws to gather otherwise undisclosed information from within an application's root.
Permalink: https://github.com/advisories/GHSA-q388-j7cw-ff7wJSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1xMzg4LWo3Y3ctZmY3d84AAcSt
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: over 1 year ago
Updated: 8 months ago
Identifiers: GHSA-q388-j7cw-ff7w, CVE-2013-3827
References:
- https://nvd.nist.gov/vuln/detail/CVE-2013-3827
- http://rhn.redhat.com/errata/RHSA-2014-0029.html
- http://www.kb.cert.org/vuls/id/526012
- https://bugs.gentoo.org/show_bug.cgi?id=CVE-2013-3827
- https://github.com/advisories/GHSA-q388-j7cw-ff7w
Affected Packages
maven:org.glassfish:javax.faces
Versions: >= 2.0.0, < 2.1.19Fixed in: 2.1.19