Moderate severityNVD Advisory· Published Jun 19, 2014· Updated May 6, 2026
CVE-2011-4367
CVE-2011-4367
Description
Multiple directory traversal vulnerabilities in MyFaces JavaServer Faces (JSF) in Apache MyFaces Core 2.0.x before 2.0.12 and 2.1.x before 2.1.6 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) ln parameter to faces/javax.faces.resource/web.xml or (2) the PATH_INFO to faces/javax.faces.resource/.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.myfaces.core:myfaces-implMaven | >= 2.0.0, < 2.0.12 | 2.0.12 |
org.apache.myfaces.core:myfaces-implMaven | >= 2.1.0, < 2.1.6 | 2.1.6 |
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
9- mail-archives.apache.org/mod_mbox/myfaces-announce/201202.mbox/%3C4F33ED1F.4070007%40apache.org%3EnvdExploitVendor AdvisoryWEB
- seclists.org/fulldisclosure/2012/Feb/150nvdExploitMailing ListThird Party AdvisoryWEB
- www.securityfocus.com/bid/51939nvdExploitThird Party AdvisoryVDB Entry
- secunia.com/advisories/47973nvdThird Party Advisory
- exchange.xforce.ibmcloud.com/vulnerabilities/73100nvdThird Party AdvisoryVDB EntryWEB
- github.com/advisories/GHSA-gjfx-9wx3-j6r7ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2011-4367ghsaADVISORY
- osvdb.org/show/osvdb/79002nvdBroken Link
- web.archive.org/web/20120213042504/http://www.securityfocus.com/bid/51939ghsaWEB
News mentions
0No linked articles in our index yet.