PT-2014-2169 · Apache · Apache Myfaces Core

Paul Nicolucci

·

Publicado

2014-06-19

·

Atualizado

2022-05-13

·

CVE-2011-4367

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache MyFaces Core versions 2.0.x through 2.0.11 Apache MyFaces Core versions 2.1.x through 2.1.5
Description Multiple directory traversal issues in Apache MyFaces Core allow remote attackers to read arbitrary files. This is achieved by including a .. (dot dot) in the ln parameter to the faces/javax.faces.resource/web.xml endpoint or in the PATH INFO to the faces/javax.faces.resource/ endpoint.
Recommendations For Apache MyFaces Core versions 2.0.x through 2.0.11, update to version 2.0.12 or later. For Apache MyFaces Core versions 2.1.x through 2.1.5, update to version 2.1.6 or later.

Exploit

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2011-4367
GHSA-GJFX-9WX3-J6R7

Produtos afetados

Apache Myfaces Core