Directory traversal in Eclipse Mojarra before 2.3.14 allows attackers to read arbitrary files via the loc parameter or con parameter.
{ "vanir_signatures": [ { "signature_version": "v1", "source": "https://github.com/eclipse-ee4j/mojarra/commit/cefbb9447e7be560e59da2da6bd7cb93776f7741", "signature_type": "Function", "target": { "function": "findPathConsideringContracts", "file": "impl/src/main/java/com/sun/faces/application/resource/ClasspathResourceHelper.java" }, "deprecated": false, "digest": { "length": 1102.0, "function_hash": "202762170446459133786542832831365494378" }, "id": "CVE-2020-6950-1eec707c" }, { "signature_version": "v1", "source": "https://github.com/eclipse-ee4j/mojarra/commit/cefbb9447e7be560e59da2da6bd7cb93776f7741", "signature_type": "Line", "target": { "file": "impl/src/main/java/com/sun/faces/application/resource/WebappResourceHelper.java" }, "deprecated": false, "digest": { "line_hashes": [ "327922468738949009520665501875403193676", "280557685043635043046617085761076948685", "149614859817110160033372584879992522944", "297201853854087322211814576356382111919" ], "threshold": 0.9 }, "id": "CVE-2020-6950-202fe355" }, { "signature_version": "v1", "source": "https://github.com/eclipse-ee4j/mojarra/commit/cefbb9447e7be560e59da2da6bd7cb93776f7741", "signature_type": "Function", "target": { "function": "getLocalePrefix", "file": "impl/src/main/java/com/sun/faces/application/resource/ResourceManager.java" }, "deprecated": false, "digest": { "length": 753.0, "function_hash": "164793891236731149737771110254800422834" }, "id": "CVE-2020-6950-3759e947" }, { "signature_version": "v1", "source": "https://github.com/eclipse-ee4j/mojarra/commit/cefbb9447e7be560e59da2da6bd7cb93776f7741", "signature_type": "Line", "target": { "file": "impl/src/main/java/com/sun/faces/application/resource/ClasspathResourceHelper.java" }, "deprecated": false, "digest": { "line_hashes": [ "327922468738949009520665501875403193676", "280557685043635043046617085761076948685", "149614859817110160033372584879992522944", "297201853854087322211814576356382111919" ], "threshold": 0.9 }, "id": "CVE-2020-6950-704c57fb" }, { "signature_version": "v1", "source": "https://github.com/eclipse-ee4j/mojarra/commit/cefbb9447e7be560e59da2da6bd7cb93776f7741", "signature_type": "Function", "target": { "function": "findPathConsideringContracts", "file": "impl/src/main/java/com/sun/faces/application/resource/WebappResourceHelper.java" }, "deprecated": false, "digest": { "length": 1113.0, "function_hash": "92691063882270755257462325335720830765" }, "id": "CVE-2020-6950-98954b3c" }, { "signature_version": "v1", "source": "https://github.com/eclipse-ee4j/mojarra/commit/cefbb9447e7be560e59da2da6bd7cb93776f7741", "signature_type": "Line", "target": { "file": "impl/src/main/java/com/sun/faces/application/resource/ResourceManager.java" }, "deprecated": false, "digest": { "line_hashes": [ "253486533298527110866937080966426277777", "317122338195403230137015481196474150719", "152375503309331982662867029571013231594", "254513352893525569632194411325804193789", "22497317531715227242858893189539738053", "110715861968449235095856192842044305285", "173356329293226279929914073126971022580", "118502403437888581242720108522154470160" ], "threshold": 0.9 }, "id": "CVE-2020-6950-ebac085b" } ] }