[ 
https://issues.apache.org/jira/browse/MYFACES-4761?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Volodymyr Siedlecki resolved MYFACES-4761.
------------------------------------------
    Resolution: Fixed

> [CVE-2026-68536] Server-Side Request Forgery / Local File Inclusion in Apache 
> MyFaces Core
> ------------------------------------------------------------------------------------------
>
>                 Key: MYFACES-4761
>                 URL: https://issues.apache.org/jira/browse/MYFACES-4761
>             Project: MyFaces Core
>          Issue Type: Bug
>    Affects Versions: 2.2.15, 2.3.11, 3.0.3, 2.3-next-M8, 4.0.3, 4.1.3
>            Reporter: Volodymyr Siedlecki
>            Assignee: Volodymyr Siedlecki
>            Priority: Major
>             Fix For: 2.3-next-M9, 5.0.0, 4.1.4, 3.0.4, 4.0.4, 2.3.12
>
>
> Severity: Moderate
> Affected versions:
>  - Apache MyFaces Core 2.2.0 to 2.2.15
>  - Apache MyFaces Core 2.3.0 to 2.3.11
>  - Apache MyFaces Core 2.3-next-M1 to 2.3-next-M8
>  - Apache MyFaces Core 3.0.0 to 3.0.3
>  - Apache MyFaces Core 4.0.0 to 4.0.3
>  - Apache MyFaces Core 4.1.0 to 4.1.3
> Description:
> A Server-Side Request Forgery (SSRF) and Local File Inclusion (LFI) 
> vulnerability was identified in Apache MyFaces Core. A remote attacker could 
> cause the application to access unintended local or remote resources through 
> specially crafted requests.
> Older unsupported versions may also be affected.
> Mitigation:
> Users are recommended to upgrade to one of the following fixed versions:
>  - Apache MyFaces Core 2.3.12
>  - Apache MyFaces Core 2.3-next-M9
>  - Apache MyFaces Core 3.0.4
>  - Apache MyFaces Core 4.0.4
>  - Apache MyFaces Core 4.1.4
> Note:
> Version 2.2.x is end-of-life and no longer maintained. It is listed for 
> awareness only. Users should upgrade to a supported release line.
> Original advisory:
> 2026-09-15



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to