CVE-2013-5855
Improper Neutralization of Input During Web Page Generation in Mojarra
EPSS 4.7%
描述
Oracle Mojarra 2.2.x before 2.2.6 and 2.1.x before 2.1.28 does not perform appropriate encoding when a (1) <h:outputText> tag or (2) EL expression is used after a scriptor style block, which allows remote attackers to conduct cross-site scripting (XSS) attacks via application-specific vectors.
如何修補 CVE-2013-5855
要修補 CVE-2013-5855,請將受影響套件升級到下列已修補版本。
- Debian/mojarra—升級至 2.2.8-1 或更新版本
- Maven/org.glassfish:javax.faces—升級至 2.2.6 或更新版本
CVE-2013-5855 正在被利用嗎?
低 — EPSS 為 4.7%,目前沒有觀察到大規模利用活動。
受影響套件(2)
- from 0, < 2.2.8-1
- >= 2.2.0, < 2.2.6