GHSA-92cv-wv2c-8899

Suggest an improvement
Source
https://github.com/advisories/GHSA-92cv-wv2c-8899
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-92cv-wv2c-8899/GHSA-92cv-wv2c-8899.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-92cv-wv2c-8899
Aliases
  • CVE-2010-2086
Published
2022-05-17T05:50:42Z
Modified
2024-02-08T16:11:36.067774Z
Summary
Apache MyFaces Cross-site Scripting vulnerability
Details

Apache MyFaces 1.1.7 and 1.2.8 (All previous versions are likely vulnerable), as used in IBM WebSphere Application Server and other applications, does not properly handle an unencrypted view state, which allows remote attackers to conduct cross-site scripting (XSS) attacks or execute arbitrary Expression Language (EL) statements via vectors that involve modifying the serialized view object.

Database specific
{
    "nvd_published_at": "2010-05-27T19:00:00Z",
    "cwe_ids": [
        "CWE-79"
    ],
    "severity": "MODERATE",
    "github_reviewed": true,
    "github_reviewed_at": "2024-02-08T15:50:25Z"
}
References

Affected packages

Maven / org.apache.myfaces.core:myfaces-core-module

Package

Name
org.apache.myfaces.core:myfaces-core-module
View open source insights on deps.dev
Purl
pkg:maven/org.apache.myfaces.core/myfaces-core-module

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
1.1.7

Maven / org.apache.myfaces.core:myfaces-core-module

Package

Name
org.apache.myfaces.core:myfaces-core-module
View open source insights on deps.dev
Purl
pkg:maven/org.apache.myfaces.core/myfaces-core-module

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.2.0
Last affected
1.2.8