[mojarra-dev] Multiple Path Traversal security issues


Latest version of Mojarra allows disclosing arbitrary resource under web context due to lack of filter in a param. I filed a report at  eclipse-ee4j/mojarra#4571. Did anyone have the chance to take a look at the issue?


