CVE-2020-6950
23Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 10%
exploitation probability
10%top 5% of all CVEs
observed exploitation
nono source reports it
Directory traversal in Eclipse Mojarra before 2.3.14 allows attackers to read arbitrary files via the loc parameter or con parameter.
Affected products
n/a · n/aReferences
https://bugs.eclipse.org/bugs/show_bug.cgi?id=550943https://github.com/eclipse-ee4j/mojarra/commit/cefbb9447e7be560e59da2da6bd7cb93776f7741https://github.com/eclipse-ee4j/mojarra/issues/4571https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.html