faces/context/PartialViewContextImpl.java in Eclipse Mojarra, as used in Mojarra for Eclipse EE4J before 2.3.10 and Mojarra JavaServer Faces before 2.2.20, allows Reflected XSS because a client window field is mishandled.
[
{
"id": "CVE-2019-17091-18b61272",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"target": {
"file": "impl/src/main/java/com/sun/faces/context/PartialViewContextImpl.java",
"function": "renderState"
},
"digest": {
"function_hash": "255508751072904989543312480708791396400",
"length": 502.0
},
"source": "https://github.com/eclipse-ee4j/mojarra/commit/a3fa9573789ed5e867c43ea38374f4dbd5a8f81f"
},
{
"id": "CVE-2019-17091-3f90b949",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"target": {
"file": "impl/src/main/java/com/sun/faces/context/PartialViewContextImpl.java"
},
"digest": {
"line_hashes": [
"100276764384938990089397896995323378259",
"308035316191811858463575403062488027130",
"53050306986765640339428499344981232771",
"189724991476151601047157279156591900058"
],
"threshold": 0.9
},
"source": "https://github.com/eclipse-ee4j/mojarra/commit/a3fa9573789ed5e867c43ea38374f4dbd5a8f81f"
}
]