OESA-2021-1229
Dashboard / Vulnerabilities / OESA-2021-1229
Summary: mojarra security update
Details: JvaServer(TM) Faces technology simplifies building user interfaces for JavaServer applications. Developers of various skill levels can quickly build web applications by: assembling reusable UI components in a page; connecting these components to an application data source; and wiring client-generated events to server-side event handlers. Security Fix(es): Directory traversal in Eclipse Mojarra before 2.3.14 allows attackers to read arbitrary files via the loc parameter or con parameter.(CVE-2020-6950)
References: https://openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2021-1229, https://nvd.nist.gov/vuln/detail/CVE-2020-6950
Affected packages
Package
Name: mojarra
Purl: pkg:rpm/openEuler/mojarra&distro=openEuler-20.03-LTS-SP1
Affected ranges
Type: ECOSYSTEM
Events:
