Directory traversal in Eclipse Mojarra before 2.3.14 allows attackers to read arbitrary files via the loc parameter or con parameter.
[ { "id": "CVE-2020-6950-1eec707c", "deprecated": false, "source": "https://github.com/eclipse-ee4j/mojarra/commit/cefbb9447e7be560e59da2da6bd7cb93776f7741", "signature_type": "Function", "target": { "function": "findPathConsideringContracts", "file": "impl/src/main/java/com/sun/faces/application/resource/ClasspathResourceHelper.java" }, "digest": { "function_hash": "202762170446459133786542832831365494378", "length": 1102.0 }, "signature_version": "v1" }, { "id": "CVE-2020-6950-202fe355", "deprecated": false, "source": "https://github.com/eclipse-ee4j/mojarra/commit/cefbb9447e7be560e59da2da6bd7cb93776f7741", "signature_type": "Line", "target": { "file": "impl/src/main/java/com/sun/faces/application/resource/WebappResourceHelper.java" }, "digest": { "threshold": 0.9, "line_hashes": [ "327922468738949009520665501875403193676", "280557685043635043046617085761076948685", "149614859817110160033372584879992522944", "297201853854087322211814576356382111919" ] }, "signature_version": "v1" }, { "id": "CVE-2020-6950-3759e947", "deprecated": false, "source": "https://github.com/eclipse-ee4j/mojarra/commit/cefbb9447e7be560e59da2da6bd7cb93776f7741", "signature_type": "Function", "target": { "function": "getLocalePrefix", "file": "impl/src/main/java/com/sun/faces/application/resource/ResourceManager.java" }, "digest": { "function_hash": "164793891236731149737771110254800422834", "length": 753.0 }, "signature_version": "v1" }, { "id": "CVE-2020-6950-704c57fb", "deprecated": false, "source": "https://github.com/eclipse-ee4j/mojarra/commit/cefbb9447e7be560e59da2da6bd7cb93776f7741", "signature_type": "Line", "target": { "file": "impl/src/main/java/com/sun/faces/application/resource/ClasspathResourceHelper.java" }, "digest": { "threshold": 0.9, "line_hashes": [ "327922468738949009520665501875403193676", "280557685043635043046617085761076948685", "149614859817110160033372584879992522944", "297201853854087322211814576356382111919" ] }, "signature_version": "v1" }, { "id": "CVE-2020-6950-98954b3c", "deprecated": false, "source": "https://github.com/eclipse-ee4j/mojarra/commit/cefbb9447e7be560e59da2da6bd7cb93776f7741", "signature_type": "Function", "target": { "function": "findPathConsideringContracts", "file": "impl/src/main/java/com/sun/faces/application/resource/WebappResourceHelper.java" }, "digest": { "function_hash": "92691063882270755257462325335720830765", "length": 1113.0 }, "signature_version": "v1" }, { "id": "CVE-2020-6950-ebac085b", "deprecated": false, "source": "https://github.com/eclipse-ee4j/mojarra/commit/cefbb9447e7be560e59da2da6bd7cb93776f7741", "signature_type": "Line", "target": { "file": "impl/src/main/java/com/sun/faces/application/resource/ResourceManager.java" }, "digest": { "threshold": 0.9, "line_hashes": [ "253486533298527110866937080966426277777", "317122338195403230137015481196474150719", "152375503309331982662867029571013231594", "254513352893525569632194411325804193789", "22497317531715227242858893189539738053", "110715861968449235095856192842044305285", "173356329293226279929914073126971022580", "118502403437888581242720108522154470160" ] }, "signature_version": "v1" } ]