CVE-2011-4367: Directory traversal
(updated )
This package allow remote attackers to read arbitrary files via a ..
in the ln
parameter to faces/javax.faces.resource/web.xml
or the PATH_INFO
to faces/javax.faces.resource/
.
References
Detect and mitigate CVE-2011-4367 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →