CVE-2018-14371
published 2018-07-18CVE-2018-14371: The getLocalePrefix function in ResourceManager.java in Eclipse Mojarra before 2.3.7 is affected by Directory Traversal via the loc parameter. A remote…
PriorityP347high7.5CVSS 3.0
AVNACLPRNUINSUCHINAN
EPSS
4.42%
90.3th percentile
The getLocalePrefix function in ResourceManager.java in Eclipse Mojarra before 2.3.7 is affected by Directory Traversal via the loc parameter. A remote attacker can download configuration files or Java bytecodes from applications.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | mojarra | — | — |
| eclipse | mojarra | < 2.3.7 | 2.3.7 |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv7.5HIGH
vendor_debian7.5LOW
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Path Traversal in Eclipse Mojarra
ghsa·2022-05-14
CVE-2018-14371 [HIGH] CWE-22 Path Traversal in Eclipse Mojarra
Path Traversal in Eclipse Mojarra
The getLocalePrefix function in ResourceManager.java in Eclipse Mojarra before 2.3.7 is affected by Directory Traversal via the loc parameter. A remote attacker can download configuration files or Java bytecodes from applications.
OSV
Path Traversal in Eclipse Mojarra
osv·2022-05-14
CVE-2018-14371 [HIGH] Path Traversal in Eclipse Mojarra
Path Traversal in Eclipse Mojarra
The getLocalePrefix function in ResourceManager.java in Eclipse Mojarra before 2.3.7 is affected by Directory Traversal via the loc parameter. A remote attacker can download configuration files or Java bytecodes from applications.
OSV
CVE-2018-14371: The getLocalePrefix function in ResourceManager
osv·2018-07-18·CVSS 7.5
CVE-2018-14371 [HIGH] CVE-2018-14371: The getLocalePrefix function in ResourceManager
The getLocalePrefix function in ResourceManager.java in Eclipse Mojarra before 2.3.7 is affected by Directory Traversal via the loc parameter. A remote attacker can download configuration files or Java bytecodes from applications.
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: ADF Faces (Eclipse Mojarra) — CVE-2018-14371
vendor_oracle·2023-04-15·CVSS 7.5
CVE-2018-14371 [HIGH] Oracle Oracle Fusion Middleware Risk Matrix: ADF Faces (Eclipse Mojarra) — CVE-2018-14371
Oracle Oracle Fusion Middleware Risk Matrix: ADF Faces (Eclipse Mojarra) vulnerability
CVE: CVE-2018-14371
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2023 (APR 2023)
Red Hat
Mojarra: Path traversal via either the loc parameter or the con parameter, incomplete fix of CVE-2018-14371
vendor_redhat·2020-02-20·CVSS 7.5
CVE-2020-6950 [HIGH] CWE-22 Mojarra: Path traversal via either the loc parameter or the con parameter, incomplete fix of CVE-2018-14371
Mojarra: Path traversal via either the loc parameter or the con parameter, incomplete fix of CVE-2018-14371
Directory traversal in Eclipse Mojarra before 2.3.14 allows attackers to read arbitrary files via the loc parameter or con parameter.
A flaw was found in Eclipse Mojarra before version 2.3.14, where it is vulnerable to a path traversal flaw via the loc parameter or the con parameter. An attacker could exploit this flaw to read arbitrary files.
Mitigation: There is no currently known mitigation for this flaw.
Package: jsf-impl (Red Hat Decision Manager 7) - Not affected
Package: jsf-impl (Red Hat JBoss Enterprise Application Platform 6) - Out of support scope
Package: jsf-impl (Red Hat JBoss Fuse 6) - Out of support scope
Package: jsf-impl (Red Hat JBoss Fuse Service Works 6) -
Red Hat
mojarra: Path traversal in ResourceManager.java:getLocalePrefix() via the loc parameter
vendor_redhat·2018-07-18·CVSS 7.5
CVE-2018-14371 [HIGH] CWE-22 mojarra: Path traversal in ResourceManager.java:getLocalePrefix() via the loc parameter
mojarra: Path traversal in ResourceManager.java:getLocalePrefix() via the loc parameter
The getLocalePrefix function in ResourceManager.java in Eclipse Mojarra before 2.3.7 is affected by Directory Traversal via the loc parameter. A remote attacker can download configuration files or Java bytecodes from applications.
Mitigation: There is no currently known mitigation for this flaw.
Package: mojarra (JBoss Developer Studio 11) - Out of support scope
Package: mojarra (Red Hat BPM Suite 6) - Out of support scope
Package: mojarra (Red Hat JBoss BRMS 6) - Out of support scope
Package: mojarra (Red Hat JBoss Data Grid 6) - Out of support scope
Package: mojarra (Red Hat JBoss Data Virtualization 6) - Out of support scope
Package: mojarra (Red Hat JBoss Enterprise Application Platform 6) -
Debian
CVE-2018-14371: mojarra - The getLocalePrefix function in ResourceManager.java in Eclipse Mojarra before 2...
vendor_debian·2018·CVSS 7.5
CVE-2018-14371 [HIGH] CVE-2018-14371: mojarra - The getLocalePrefix function in ResourceManager.java in Eclipse Mojarra before 2...
The getLocalePrefix function in ResourceManager.java in Eclipse Mojarra before 2.3.7 is affected by Directory Traversal via the loc parameter. A remote attacker can download configuration files or Java bytecodes from applications.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-6950 Mojarra: Path traversal via either the loc parameter or the con parameter, incomplete fix of CVE-2018-14371
bugzilla·2020-02-20·CVSS 7.5
CVE-2020-6950 [HIGH] CVE-2020-6950 Mojarra: Path traversal via either the loc parameter or the con parameter, incomplete fix of CVE-2018-14371
CVE-2020-6950 Mojarra: Path traversal via either the loc parameter or the con parameter, incomplete fix of CVE-2018-14371
Eclipse Mojarra before version 2.3.14 is vulnerable to a path traversal flaw via either the loc parameter or the con parameter. An attacker could exploit this to read arbitrary files. It was reported as CVE-2019-0199, but it was an incomplete fix.
Upstream Patch:
https://github.com/eclipse-ee4j/mojarra/commit/1b434748d9239f42eae8aa7d37d7a0930c061e24
https://github.com/eclipse-ee4j/mojarra/commit/cefbb9447e7be560e59da2da6bd7cb93776f7741
Discussion:
External References:
https://github.com/javaserverfaces/mojarra/issues/4364
https://github.com/eclipse-ee4j/mojarra/commit/1b434748d9239f42eae8aa7d37d7a0930c061e24
https://bugs.eclipse.org/bugs/show_bug.cgi?id=550943
http
Bugzilla
CVE-2018-14371 mojarra: Path traversal in ResourceManager.java:getLocalePrefix() via the loc parameter [fedora-all]
bugzilla·2018-07-24·CVSS 7.5
CVE-2018-14371 [HIGH] CVE-2018-14371 mojarra: Path traversal in ResourceManager.java:getLocalePrefix() via the loc parameter [fedora-all]
CVE-2018-14371 mojarra: Path traversal in ResourceManager.java:getLocalePrefix() via the loc parameter [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this iss
Bugzilla
CVE-2018-14371 mojarra: Path traversal in ResourceManager.java:getLocalePrefix() via the loc parameter
bugzilla·2018-07-24·CVSS 7.5
CVE-2018-14371 [HIGH] CVE-2018-14371 mojarra: Path traversal in ResourceManager.java:getLocalePrefix() via the loc parameter
CVE-2018-14371 mojarra: Path traversal in ResourceManager.java:getLocalePrefix() via the loc parameter
Eclipse Mojarra before version 2.3.5 is vulnerable to a path traversal falw in the ResourceManager.java:getLocalePrefix() function via the loc parameter. An attacker could exploit this to read arbitrary files.
Upstream Patch:
https://github.com/eclipse-ee4j/mojarra/commit/1b434748d9239f42eae8aa7d37d7a0930c061e24
Discussion:
Created mojarra tracking bugs for this issue:
Affects: fedora-all [bug 1607710]
---
This vulnerability is out of security support scope for the following products:
* Red Hat JBoss Operations Network 3
* Red Hat JBoss Fuse 6
* Red Hat JBoss SOA Platform 5
* Red Hat Enterprise Application Platform 6
* Red Hat JBoss Data Virtualization & Services 6
* Red Hat JBos
2018-07-18
Published