Information disclosure vulnerability in Apache MyFaces Core 2.0.1 through 2.0.10 and 2.1.0 through 2.1.4 allows remote attackers to inject EL expressions via crafted parameters.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| org.apache.myfaces.core:myfaces-core-module(Maven) | 2.0.1 | 2.0.11 | N/A |
| org.apache.myfaces.core:myfaces-core-module(Maven) | 2.1.0 | 2.1.5 | N/A |
CVSS Metrics