GHSA-wrxx-w58g-3gqpHighCVSS 7.5

In Eclipse Mojarra versions 2.3 and following, URL handing in `DefaultFaceletFactory` does not...

Published
August 5, 2026
Last Modified
August 5, 2026

🔗 CVE IDs covered (1)

📋 Description

In Eclipse Mojarra versions 2.3 and following, URL handing in DefaultFaceletFactory does not properly sanitize and/or block remote URLs, allowing an attacker to specify a URL to a remote Facelet which will be included and processed as part of the normal request, with the privileges of the target server. This could allow access to restricted files such as WEB-INF/web.xml or /etc/passwd.

🔗 References (4)