Eclipse Mojarra是美国Eclipse基金会开源的一款基于Java的Web用户界面框架。 Eclipse Mojarra 2.3版本至5.0及之前版本存在安全漏洞,该漏洞源于DefaultFaceletFactory对远程URL的清理和阻止不当,可能导致攻击者将远程Facelet作为正常请求的一部分纳入并处理,从而以目标服务器权限访问受限文件,如WEB-INF/web.xml或/etc/passwd。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Eclipse Foundation | Eclipse Mojarra | 2.3≤ 5.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Eclipse Foundation | Eclipse Mojarra | 2.3 ~ 5.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-60009 | 8.8 HIGH | Eclipse Theia 路径遍历漏洞 |
| CVE-2026-12609 | 7.5 HIGH | Eclipse Theia 路径遍历漏洞 |
| CVE-2026-61891 | 7.5 HIGH | Eclipse Theia 信息泄露漏洞 |
| CVE-2026-14574 | 5.7 MEDIUM | Eclipse Theia 输入验证错误漏洞 |
| CVE-2026-14304 | 4.6 MEDIUM | Eclipse Accessibility Tools Framework 输入验证错误漏洞 |
No comments yet