CVE-2019-17091

faces/context/PartialViewContextImpl.java in Eclipse Mojarra, as used in Mojarra for Eclipse EE4J before 2.3.10 and Mojarra JavaServer Faces before 2.2.20, allows Reflected XSS because a client window field is mishandled.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:eclipse:mojarra:*:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mojarra_javaserver_faces:*:*:*:*:*:*:*:*

Information

Published : 2019-10-02 14:15

Updated : 2022-02-07 16:15


NVD link : CVE-2019-17091

Mitre link : CVE-2019-17091


JSON object : View

Products Affected

eclipse

  • mojarra

oracle

  • mojarra_javaserver_faces
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')