bugs.eclipse.org
https://bugs.eclipse.org/bugs/show_bug.cgi?id=550943 CVE-2020-6950
MEDIUMNuclei
Directory traversal in Eclipse Mojarra
Record summary
CVE-2020-6950 has a selected CVSS score of 6.5 (medium); EIP currently links 1 Nuclei template.
Description
Directory traversal in Eclipse Mojarra before 2.3.14 allows attackers to read arbitrary files via the loc parameter or con parameter.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
org.glassfish:mojarra-parentBrowse Maven / org.glassfish:mojarra-parent | GitHub Advisory | Before 2.3.14 · Fixed in 2.3.14 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMEclipse Mojarra - Local File ReadCVSS 6.5
Directory traversal in Eclipse Mojarra before 2.3.14 allows attackers to read arbitrary files via the loc parameter or con parameter.
Impact
Attackers can read arbitrary files from the server including configuration files and credentials, potentially leading to further exploitation and data exposure.
Remediation
Upgrade to Eclipse Mojarra version 2.3.14 or later.
WeaknessesCWE-22
Authorsiamnoooob, pdresearch
Template tagscvecve2020mojarralfieclipsevuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:eclipse:mojarra:*:*:*:*:*:*:*:*
Shodan: html:"javax.faces.resource"
Shodan: http.html:"javax.faces.viewstate"
Shodan: http.html:"javax.faces.resource"
FOFA: body="javax.faces.ViewState"
FOFA: body="javax.faces.viewstate"
FOFA: body="javax.faces.resource"
https://github.com/eclipse-ee4j/mojarra/commit/cefbb9447e7be560e59da2da6bd7cb93776f7741 https://github.com/eclipse-ee4j/mojarra/issues/4571 https://nvd.nist.gov/vuln/detail/CVE-2020-6950 https://bugs.eclipse.org/bugs/show_bug.cgi?id=550943 https://www.oracle.com/security-alerts/cpuapr2022.html
Source: ProjectDiscovery
References
8github.com
https://github.com/eclipse-ee4j/mojarra github.com
https://github.com/eclipse-ee4j/mojarra/commit/cefbb9447e7be560e59da2da6bd7cb93776f7741 github.com
https://github.com/eclipse-ee4j/mojarra/issues/4571 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-6950 oracle.com
https://www.oracle.com/security-alerts/cpuapr2022.html oracle.com
https://www.oracle.com/security-alerts/cpujan2022.html oracle.com
https://www.oracle.com/security-alerts/cpuoct2021.html