LWN.net Logo

mojarra: code injection

Package(s):mojarra CVE #(s):CVE-2011-4358
Created:December 7, 2011 Updated:December 7, 2011
Description: Mojarra (a JavaServer Faces implementation) can be made to execute untrusted values as EL expressions in some configurations.
Alerts:
Debian DSA-2359-1 2011-12-06

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds