High severity7.5NVD Advisory· Published Jul 18, 2018· Updated Jun 17, 2026
CVE-2018-14371
CVE-2018-14371
Description
The getLocalePrefix function in ResourceManager.java in Eclipse Mojarra before 2.3.7 is affected by Directory Traversal via the loc parameter. A remote attacker can download configuration files or Java bytecodes from applications.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.glassfish:mojarra-parentMaven | < 2.3.7 | 2.3.7 |
Affected products
1Patches
Vulnerability mechanics
References
5- github.com/eclipse-ee4j/mojarra/commit/1b434748d9239f42eae8aa7d37d7a0930c061e24nvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-43q7-q5vp-3g68ghsaADVISORY
- github.com/javaserverfaces/mojarra/issues/4364nvdThird Party Advisory
- nvd.nist.gov/vuln/detail/CVE-2018-14371ghsaADVISORY
- github.com/eclipse-ee4j/mojarra/pull/4384ghsaWEB
News mentions
0No linked articles in our index yet.