HIGH🇵🇱 Wersja polska

CVE-2026-46581

CVSS 7.5v3.1pub. 2026-08-05upd. 2026-08-10

In Eclipse Mojarra versions 2.3 and following, URL handing in `DefaultFaceletFactory` does not properly sanitize and/or block remote URLs, allowing an attacker to specify a URL to a remote Facelet which will be included and processed as part of the normal request, with the privileges of the target server. This could allow access to restricted files such as `WEB-INF/web.xml` or `/etc/passwd`.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
  • Eclipse Mojarra

    APP
    Eclipse
    5.0.02.3.0 – 4.1.13
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Path Traversal
CWE
References

Related vulnerabilities

CVE-2018-14371HIGH7.5same product

The getLocalePrefix function in ResourceManager.java in Eclipse Mojarra before 2.3.7 is affected by Directory ...

CVE-2020-6950MEDIUM6.5same product

Directory traversal in Eclipse Mojarra before 2.3.14 allows attackers to read arbitrary files via the loc para...

CVE-2019-17091MEDIUM6.1same product

faces/context/PartialViewContextImpl.java in Eclipse Mojarra, as used in Mojarra for Eclipse EE4J before 2.3.1...

CVE-2026-12605CRITICAL9.6PL ✓same vendor

Eclipse GlassFish: CSRF+SSRF w DownloadServlet umożliwia przejęcie domeny

CVE-2026-60007CRITICAL9.1PL ✓same vendor

Eclipse Milo: padding oracle w uwierzytelnianiu OPC-UA umożliwia odzyskanie hasła