PT-2018-3873 · Eclipse · Eclipse Mojarra

Publicado

2018-07-18

·

Atualizado

2022-05-14

·

CVE-2018-14371

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Eclipse Mojarra versions prior to 2.3.7
Description The issue concerns the getLocalePrefix function in ResourceManager.java, which is affected by a directory traversal vulnerability via the loc parameter. This allows a remote attacker to download configuration files or Java bytecodes from applications. The vulnerability is related to incorrect restriction of a directory path name with limited access, enabling an attacker to gain unauthorized access to protected information.
Recommendations For Eclipse Mojarra versions prior to 2.3.7, update to version 2.3.7 or later to resolve the issue. As a temporary workaround, consider restricting access to the getLocalePrefix function in ResourceManager.java to minimize the risk of exploitation. Avoid using the loc parameter in vulnerable API endpoints until the issue is resolved.

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-02664
CVE-2018-14371
GHSA-43Q7-Q5VP-3G68
RHSA-2020:2063
RHSA-2020:2511
RHSA-2020:2512
RHSA-2020:2513

Produtos afetados

Eclipse Mojarra