CVE-2012-2672
Publication date 17 June 2012
Last updated 24 July 2024
Ubuntu priority
Oracle Mojarra 2.1.7 does not properly "clean up" the FacesContext reference during startup, which allows local users to obtain context information an access resources from another WAR file by calling the FacesContext.getCurrentInstance function.
Status
Package | Ubuntu Release | Status |
---|---|---|
mojarra | ||
18.04 LTS bionic |
Not affected
|
|
16.04 LTS xenial |
Not affected
|
|
14.04 LTS trusty | Not in release | |
Notes
ebarretto
According to Debian: Only affected in combination with EAP6/AS7 application servers, not shipped in Debian
References
Other references
- https://issues.jboss.org/browse/JBPAPP-9197
- http://xforce.iss.net/xforce/xfdb/76179
- http://www.openwall.com/lists/oss-security/2012/06/07/3
- http://www.openwall.com/lists/oss-security/2012/06/07/2
- http://secunia.com/advisories/49284
- http://java.net/jira/browse/JAVASERVERFACES-2436
- https://www.cve.org/CVERecord?id=CVE-2012-2672