org.apache.myfaces.shared:myfaces-shared-impl@2.0.0 vulnerabilities

Shared project renamed for use in MyFaces Impl

Direct Vulnerabilities

Known vulnerabilities in the org.apache.myfaces.shared:myfaces-shared-impl package. This does not include vulnerabilities belonging to this package’s dependencies.

Vulnerability Vulnerable Version
Cryptographic Issues

org.apache.myfaces.shared:myfaces-shared-impl is a Shared Project renamed for use in the MyFaces Impl jar.

Affected versions of this package are vulnerable to Cryptographic Issues as it uses an encrypted View State without a Message Authentication Code (MAC), which makes it easier for remote attackers to perform successful modifications of the View State via a padding oracle attack.

How to fix Cryptographic Issues?

Upgrade org.apache.myfaces.shared:myfaces-shared-impl to version 2.0.1 or higher.