漏洞信息详情
Eclipse Mojarra 跨站脚本漏洞
漏洞简介
Mojarra是一款JavaServer Faces规范的实现。
Eclipse Mojarra中的faces/context/PartialViewContextImpl.java文件存在跨站脚本漏洞。该漏洞源于WEB应用缺少对客户端数据的正确验证。攻击者可利用该漏洞执行客户端代码。以下产品及版本受到影响:Eclipse Mojarra 2.3.10之前版本;Oracle Mojarra JavaServer Faces 2.2.20之前版本。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://github.com/eclipse-ee4j/mojarra/pull/4567
参考网址
来源:MISC
链接:https://github.com/javaserverfaces/mojarra/compare/2.2.19...2.2.20
来源:MISC
链接:https://github.com/eclipse-ee4j/mojarra/commit/8f70f2bd024f00ecd5b3dcca45df73edda29dcee
来源:MISC
链接:https://github.com/javaserverfaces/mojarra/commit/ae1c234d0a6750822ac69d4ae26d90e3571f27fe
来源:MISC
链接:https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
来源:N/A
链接:https://www.oracle.com/security-alerts/cpuapr2020.html
来源:github.com
链接:https://github.com/javaserverfaces/mojarra/commit/f61935cd39f34329fbf27b1972a506fbdd0ab4d4
来源:github.com
链接:https://github.com/eclipse-ee4j/mojarra/pull/4567
来源:github.com
链接:https://github.com/eclipse-ee4j/mojarra/issues/4556
来源:github.com
链接:https://github.com/eclipse-ee4j/mojarra/files/3039198/advisory.txt
来源:github.com
链接:https://github.com/eclipse-ee4j/mojarra/compare/2.3.9-RELEASE...2.3.10-RELEASE
来源:github.com
链接:https://github.com/eclipse-ee4j/mojarra/commit/a3fa9573789ed5e867c43ea38374f4dbd5a8f81f
来源:bugs.eclipse.org
链接:https://bugs.eclipse.org/bugs/show_bug.cgi?id=548244
来源:MISC
链接:https://www.oracle.com/security-alerts/cpujan2021.html
来源:www.oracle.com
链接:https://www.oracle.com/security-alerts/cpujan2020.html
来源:MISC
链接:https://www.oracle.com/security-alerts/cpuoct2020.html
来源:MISC
链接:https://www.oracle.com/security-alerts/cpujul2020.html
来源:www.oracle.com
链接:https://www.oracle.com/technetwork/security-advisory/cpuoct2019verbose-5072833.html
来源:www.oracle.com
链接:https://www.oracle.com/security-alerts/cpuoct2020.html
来源:www.oracle.com
链接:https://www.oracle.com/security-alerts/cpujul2020.html
来源:nvd.nist.gov
链接:https://nvd.nist.gov/vuln/detail/CVE-2019-17091
来源:www.oracle.com
链接:https://www.oracle.com/security-alerts/cpujan2021.html
来源:vigilance.fr
链接:https://vigilance.fr/vulnerability/Oracle-Fusion-Middleware-vulnerabilities-of-January-2021-34371
来源:www.oracle.com
链接:https://www.oracle.com/security-alerts/cpujan2020verbose.html
受影响实体
暂无
补丁
- Eclipse EE4J Mojarra 安全漏洞的修复措施<!--2019-10-2-->
还没有评论,来说两句吧...