Description
Directory traversal in Eclipse Mojarra before 2.3.14 allows attackers to read arbitrary files via the loc parameter or con parameter.
Remediation
References
https://bugs.eclipse.org/bugs/show_bug.cgi?id=550943
https://github.com/eclipse-ee4j/mojarra/commit/cefbb9447e7be560e59da2da6bd7cb93776f7741
https://github.com/eclipse-ee4j/mojarra/issues/4571
https://www.oracle.com/security-alerts/cpuapr2022.html
https://www.oracle.com/security-alerts/cpujan2022.html
https://www.oracle.com/security-alerts/cpuoct2021.html
Related Vulnerabilities
CVE-2018-14042 Vulnerability in maven package org.fujion.webjars:bootstrap
CVE-2020-16040 Vulnerability in maven package org.webjars.npm:electron
CVE-2023-37957 Vulnerability in maven package io.jenkins.plugins:pipeline-restful-api
CVE-2023-33949 Vulnerability in maven package com.liferay.portal:release.portal.bom
CVE-2020-2286 Vulnerability in maven package org.jenkins-ci.plugins:role-strategy