PT-2018-3873 · Eclipse · Eclipse Mojarra

Published

2018-07-18

·

Updated

2022-05-14

·

CVE-2018-14371

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Eclipse Mojarra versions prior to 2.3.7
Description The issue concerns the getLocalePrefix function in ResourceManager.java, which is affected by a directory traversal vulnerability via the loc parameter. This allows a remote attacker to download configuration files or Java bytecodes from applications. The vulnerability is related to incorrect restriction of a directory path name with limited access, enabling an attacker to gain unauthorized access to protected information.
Recommendations For Eclipse Mojarra versions prior to 2.3.7, update to version 2.3.7 or later to resolve the issue. As a temporary workaround, consider restricting access to the getLocalePrefix function in ResourceManager.java to minimize the risk of exploitation. Avoid using the loc parameter in vulnerable API endpoints until the issue is resolved.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-02664
CVE-2018-14371
GHSA-43Q7-Q5VP-3G68
RHSA-2020:2063
RHSA-2020:2511
RHSA-2020:2512
RHSA-2020:2513

Affected Products

Eclipse Mojarra