Medium severity6.5NVD Advisory· Published Jun 2, 2021· Updated Jun 17, 2026
CVE-2020-6950
CVE-2020-6950
Description
Directory traversal in Eclipse Mojarra before 2.3.14 allows attackers to read arbitrary files via the loc parameter or con parameter.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.glassfish:mojarra-parentMaven | < 2.3.14 | 2.3.14 |
Affected products
1Patches
Vulnerability mechanics
References
8- github.com/eclipse-ee4j/mojarra/commit/cefbb9447e7be560e59da2da6bd7cb93776f7741nvdPatchThird Party AdvisoryWEB
- www.oracle.com/security-alerts/cpuapr2022.htmlnvdPatchThird Party AdvisoryWEB
- www.oracle.com/security-alerts/cpujan2022.htmlnvdPatchThird Party AdvisoryWEB
- www.oracle.com/security-alerts/cpuoct2021.htmlnvdPatchThird Party AdvisoryWEB
- bugs.eclipse.org/bugs/show_bug.cginvdIssue TrackingVendor AdvisoryWEB
- github.com/advisories/GHSA-rpq8-mmwh-q9hmghsaADVISORY
- github.com/eclipse-ee4j/mojarra/issues/4571nvdIssue TrackingThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2020-6950ghsaADVISORY
News mentions
0No linked articles in our index yet.