CVE-2013-3827
Path Traversal in Eclipse Mojarra
EPSS 32.4%
Description
Multiple path traversal flaws where found in Mojarra JSF2 implementation for identifying resources by name or from libraries. An unauthenticated remote attacker can use these flaws to gather otherwise undisclosed information from within an application's root.
How to fix CVE-2013-3827
To remediate CVE-2013-3827, upgrade the affected package to a fixed version below.
- Maven/org.glassfish:javax.faces—upgrade to 2.1.19 or later
Is CVE-2013-3827 being exploited?
Moderate — EPSS is 32.4%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- >= 2.0.0, < 2.1.19