Page 1 of 1

CVE-2017-1000486 on PrimeFaces 6.2 ?

Posted: 05 Dec 2018, 19:58
by gallog
Hi,
we are upgrading our PrimeFaces 6.1 installation due to CVE-2017-1000486 vulnerability.
We think that the problem has been solved by this commit
https://github.com/primefaces/primeface ... e8772fd3d9
and already fixed in community 6.2 version.

Can you confirm that you think this version is not affected by CVE-2017-1000486 ?

Regards,
Gianluca

Re: CVE-2017-1000486 on PrimeFaces 6.2 ?

Posted: 06 Dec 2018, 10:20
by tandraschko