[MAVEN:GHSA-JQ6G-P65R-44XR] Apache MyFaces Vulnerable to EL Injection

Severity High
Affected Packages 2
Fixed Packages 2
CVEs 1

Information disclosure vulnerability in Apache MyFaces Core 2.0.1 through 2.0.10 and 2.1.0 through 2.1.4 allows remote attackers to inject EL expressions via crafted parameters.

ID
MAVEN:GHSA-JQ6G-P65R-44XR
Severity
high
URL
https://github.com/advisories/GHSA-jq6g-p65r-44xr
Published
2022-05-17T00:29:01
(2 years ago)
Modified
2024-01-17T22:25:44
(8 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.apache.myfaces.core/myfaces-core-module org.apache.myfaces.core myfaces-core-module >= 2.1.0 <= 2.1.4
Fixed pkg:maven/org.apache.myfaces.core/myfaces-core-module org.apache.myfaces.core myfaces-core-module = 2.1.5
Affected pkg:maven/org.apache.myfaces.core/myfaces-core-module org.apache.myfaces.core myfaces-core-module >= 2.0.1 <= 2.0.10
Fixed pkg:maven/org.apache.myfaces.core/myfaces-core-module org.apache.myfaces.core myfaces-core-module = 2.0.11
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...