Directory traversal in Eclipse Mojarra before 2.3.14 allows attackers to read arbitrary files via the loc parameter or con parameter.
[
{
"id": "CVE-2020-6950-1eec707c",
"source": "https://github.com/eclipse-ee4j/mojarra/commit/cefbb9447e7be560e59da2da6bd7cb93776f7741",
"deprecated": false,
"signature_version": "v1",
"target": {
"function": "findPathConsideringContracts",
"file": "impl/src/main/java/com/sun/faces/application/resource/ClasspathResourceHelper.java"
},
"digest": {
"length": 1102.0,
"function_hash": "202762170446459133786542832831365494378"
},
"signature_type": "Function"
},
{
"id": "CVE-2020-6950-202fe355",
"source": "https://github.com/eclipse-ee4j/mojarra/commit/cefbb9447e7be560e59da2da6bd7cb93776f7741",
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "impl/src/main/java/com/sun/faces/application/resource/WebappResourceHelper.java"
},
"digest": {
"threshold": 0.9,
"line_hashes": [
"327922468738949009520665501875403193676",
"280557685043635043046617085761076948685",
"149614859817110160033372584879992522944",
"297201853854087322211814576356382111919"
]
},
"signature_type": "Line"
},
{
"id": "CVE-2020-6950-3759e947",
"source": "https://github.com/eclipse-ee4j/mojarra/commit/cefbb9447e7be560e59da2da6bd7cb93776f7741",
"deprecated": false,
"signature_version": "v1",
"target": {
"function": "getLocalePrefix",
"file": "impl/src/main/java/com/sun/faces/application/resource/ResourceManager.java"
},
"digest": {
"length": 753.0,
"function_hash": "164793891236731149737771110254800422834"
},
"signature_type": "Function"
},
{
"id": "CVE-2020-6950-704c57fb",
"source": "https://github.com/eclipse-ee4j/mojarra/commit/cefbb9447e7be560e59da2da6bd7cb93776f7741",
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "impl/src/main/java/com/sun/faces/application/resource/ClasspathResourceHelper.java"
},
"digest": {
"threshold": 0.9,
"line_hashes": [
"327922468738949009520665501875403193676",
"280557685043635043046617085761076948685",
"149614859817110160033372584879992522944",
"297201853854087322211814576356382111919"
]
},
"signature_type": "Line"
},
{
"id": "CVE-2020-6950-98954b3c",
"source": "https://github.com/eclipse-ee4j/mojarra/commit/cefbb9447e7be560e59da2da6bd7cb93776f7741",
"deprecated": false,
"signature_version": "v1",
"target": {
"function": "findPathConsideringContracts",
"file": "impl/src/main/java/com/sun/faces/application/resource/WebappResourceHelper.java"
},
"digest": {
"length": 1113.0,
"function_hash": "92691063882270755257462325335720830765"
},
"signature_type": "Function"
},
{
"id": "CVE-2020-6950-ebac085b",
"source": "https://github.com/eclipse-ee4j/mojarra/commit/cefbb9447e7be560e59da2da6bd7cb93776f7741",
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "impl/src/main/java/com/sun/faces/application/resource/ResourceManager.java"
},
"digest": {
"threshold": 0.9,
"line_hashes": [
"253486533298527110866937080966426277777",
"317122338195403230137015481196474150719",
"152375503309331982662867029571013231594",
"254513352893525569632194411325804193789",
"22497317531715227242858893189539738053",
"110715861968449235095856192842044305285",
"173356329293226279929914073126971022580",
"118502403437888581242720108522154470160"
]
},
"signature_type": "Line"
}
]