{"id":"GHSA-gjfx-9wx3-j6r7","summary":"Apache MyFaces Vulnerable to Path Traversal","details":"Multiple directory traversal vulnerabilities in MyFaces JavaServer Faces (JSF) in Apache MyFaces Core 2.0.x before 2.0.12 and 2.1.x before 2.1.6 allow remote attackers to read arbitrary files via a `..` (dot dot) in the (1) ln parameter to `faces/javax.faces.resource/web.xml` or (2) the `PATH_INFO` to `faces/javax.faces.resource/`.","aliases":["CVE-2011-4367"],"modified":"2024-11-29T05:41:33.102581Z","published":"2022-05-13T01:24:34Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2022-11-02T00:42:02Z","nvd_published_at":"2014-06-19T14:55:00Z","cwe_ids":["CWE-22"],"severity":"MODERATE"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2011-4367"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/73100"},{"type":"WEB","url":"https://web.archive.org/web/20120213042504/http://www.securityfocus.com/bid/51939"},{"type":"WEB","url":"http://mail-archives.apache.org/mod_mbox/myfaces-announce/201202.mbox/%3C4F33ED1F.4070007%40apache.org%3E"},{"type":"WEB","url":"http://seclists.org/fulldisclosure/2012/Feb/150"}],"affected":[{"package":{"name":"org.apache.myfaces.core:myfaces-impl","ecosystem":"Maven","purl":"pkg:maven/org.apache.myfaces.core/myfaces-impl"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.0.0"},{"fixed":"2.0.12"}]}],"versions":["2.0.0","2.0.1","2.0.10","2.0.11","2.0.2","2.0.3","2.0.4","2.0.5","2.0.6","2.0.7","2.0.8","2.0.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-gjfx-9wx3-j6r7/GHSA-gjfx-9wx3-j6r7.json"}},{"package":{"name":"org.apache.myfaces.core:myfaces-impl","ecosystem":"Maven","purl":"pkg:maven/org.apache.myfaces.core/myfaces-impl"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.1.0"},{"fixed":"2.1.6"}]}],"versions":["2.1.0","2.1.1","2.1.2","2.1.3","2.1.4","2.1.5"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-gjfx-9wx3-j6r7/GHSA-gjfx-9wx3-j6r7.json"}}],"schema_version":"1.9.0"}