Apache MyFaces CVE-2011-4343 Information Disclosure Vulnerability
BID:50912
Info
Apache MyFaces CVE-2011-4343 Information Disclosure Vulnerability
| Bugtraq ID: | 50912 |
| Class: | Design Error |
| CVE: |
CVE-2011-4343 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 06 2011 12:00AM |
| Updated: | Dec 06 2011 12:00AM |
| Credit: | BalusC and Frederick Kämpfer. |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Apache MyFaces CVE-2011-4343 Information Disclosure Vulnerability
Apache MyFaces is prone to a remote information-disclosure vulnerability.
Remote attackers can exploit this issue to obtain sensitive information that will aid in further attacks.
The following versions are affected:
Apache MyFaces 2.0.1 through 2.0.10
Apache MyFaces 2.1.0 through 2.1.4
Apache MyFaces is prone to a remote information-disclosure vulnerability.
Remote attackers can exploit this issue to obtain sensitive information that will aid in further attacks.
The following versions are affected:
Apache MyFaces 2.0.1 through 2.0.10
Apache MyFaces 2.1.0 through 2.1.4
Exploit / POC
Apache MyFaces CVE-2011-4343 Information Disclosure Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Apache MyFaces CVE-2011-4343 Information Disclosure Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Apache MyFaces CVE-2011-4343 Information Disclosure Vulnerability
References:
References:
- Apache CVE-2011-4343 Patch (Apache)
- includeViewParameters re-evaluates param/model values as EL expressions (Sun)
- includeViewParameters re-evaluates param/model values as EL expressions (Apache)
- MyFaces Homepage (Apache Software Foundation)