CVE-2011-4367: Directory traversal
(updated )
This package allow remote attackers to read arbitrary files via a .. in the ln parameter to faces/javax.faces.resource/web.xml or the PATH_INFO to faces/javax.faces.resource/.
References
Code Behaviors & Features
Detect and mitigate CVE-2011-4367 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →