{"id":"GHSA-rpq8-mmwh-q9hm","summary":"Directory traversal in Eclipse Mojarra","details":"Directory traversal in Eclipse Mojarra before 2.3.14 allows attackers to read arbitrary files via the loc parameter or con parameter.","aliases":["CVE-2020-6950"],"modified":"2023-11-01T04:53:26.860174Z","published":"2021-09-01T18:23:58Z","database_specific":{"nvd_published_at":"2021-06-02T16:15:00Z","cwe_ids":["CWE-22"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2021-06-03T21:21:35Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-6950"},{"type":"WEB","url":"https://github.com/eclipse-ee4j/mojarra/issues/4571"},{"type":"WEB","url":"https://github.com/eclipse-ee4j/mojarra/commit/cefbb9447e7be560e59da2da6bd7cb93776f7741"},{"type":"WEB","url":"https://bugs.eclipse.org/bugs/show_bug.cgi?id=550943"},{"type":"PACKAGE","url":"https://github.com/eclipse-ee4j/mojarra"},{"type":"WEB","url":"https://www.oracle.com/security-alerts/cpuapr2022.html"},{"type":"WEB","url":"https://www.oracle.com/security-alerts/cpujan2022.html"},{"type":"WEB","url":"https://www.oracle.com/security-alerts/cpuoct2021.html"}],"affected":[{"package":{"name":"org.glassfish:mojarra-parent","ecosystem":"Maven","purl":"pkg:maven/org.glassfish/mojarra-parent"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.3.14"}]}],"versions":["2.3.10","2.3.11","2.3.12","2.3.13","2.3.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/09/GHSA-rpq8-mmwh-q9hm/GHSA-rpq8-mmwh-q9hm.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}