In Eclipse Mojarra versions 2.3 and following, URL handing in DefaultFaceletFactory does not properly sanitize and/or block remote URLs, allowing an attacker to specify a URL to a remote Facelet which will be included and processed as part of the normal request, with the privileges of the target server. This could allow access to restricted files such as WEB-INF/web.xml or /etc/passwd.
Eclipse Mojarra before version 2.3.5 is vulnerable to a path traversal falw in the ResourceManager.java:getLocalePrefix() function via the loc parameter. An attacker could exploit this to read arbitrary files.
Upstream Patch:
https://github.com/eclipse-ee4j/mojarra/commit/1b434748d9239f42eae8aa7d37d7a0930c061e24
A flaw was found in Eclipse Mojarra before version 2.3.14, where it is vulnerable to a path traversal flaw via the loc parameter or the con parameter. An attacker could exploit this flaw to read arbitrary files.
Eclipse Mojarra before version 2.3.5 is vulnerable to a path traversal falw in the ResourceManager.java:getLocalePrefix() function via the loc parameter. An attacker could exploit this to read arbitrary files.
Upstream Patch:
https://github.com/eclipse-ee4j/mojarra/commit/1b434748d9239f42eae8aa7d37d7a0930c061e24