Bugzilla will be upgraded to version 5.0 on a still to be determined date in the near future. The original upgrade date has been delayed.
Bug 1038898 - (CVE-2013-3827) CVE-2013-3827 Mojarra JSF2: Multiple Information Disclosure flaws due to unsafe path traversal
CVE-2013-3827 Mojarra JSF2: Multiple Information Disclosure flaws due to unsa...
Status: CLOSED ERRATA
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
high Severity high
: ---
: ---
Assigned To: Red Hat Product Security
impact=important,public=20131017,repo...
: Security
Depends On: 1038913 1038915 1038916
Blocks: 991853 1035974 1038927
  Show dependency treegraph
 
Reported: 2013-12-06 00:19 EST by Arun Babu Neelicattu
Modified: 2015-02-15 16:52 EST (History)
21 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2014-01-15 13:33:07 EST
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2014:0029 normal SHIPPED_LIVE Important: Red Hat JBoss Data Grid 6.2.0 update 2014-01-15 17:45:50 EST

  None (edit)
Description Arun Babu Neelicattu 2013-12-06 00:19:54 EST
Multiple path traversal flaws where found in Mojarra JSF2 implementation for identifying resources by name or from libraries. An unauthenticated remote attacker can use these flaws to gather otherwise undisclosed information from within an application's root.

References:
[1] http://security.coverity.com/advisory/2013/Oct/two-path-traversal-defects-in-oracles-jsf2-implementation.html
[2] http://www.kb.cert.org/vuls/id/526012
[3] http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html
[4] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3827

Affects: 2.0 - 2.1.18
Fixed In: 2.1.19

Upstream Fix commit: 
https://java.net/projects/mojarra/sources/svn/revision/11603
https://java.net/projects/mojarra/sources/svn/revision/11606
Comment 6 errata-xmlrpc 2014-01-15 12:47:14 EST
This issue has been addressed in following products:

  Red Hat JBoss Data Grid 6.2.0

Via RHSA-2014:0029 https://rhn.redhat.com/errata/RHSA-2014-0029.html

Note You need to log in before you can comment on or make changes to this bug.