CVE-2022-2712

CVSS v3.1 7.5 (High)
75% Progress
EPSS 0.25 % (65th)
0.25% Progress
Affected Products 1
Advisories 1

In Eclipse GlassFish versions 5.1.0 to 6.2.5, there is a vulnerability in relative path traversal because it does not filter request path starting with './'. Successful exploitation could allow an remote unauthenticated attacker to access critical data, such as configuration files and deployed application source code.

Weaknesses
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE Status
PUBLISHED
CNA
Eclipse Foundation
Published Date
2023-01-27 10:15:09
(20 months ago)
Updated Date
2023-11-07 03:46:51
(10 months ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Eclipse Glassfish from 5.1.0 version and 6.2.5 and prior versions cpe:2.3:a:eclipse:glassfish >= 5.1.0 <= 6.2.5
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...