CVE-2022-2712

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
27/01/2023
Last modified:
07/11/2023

Description

In Eclipse GlassFish versions 5.1.0 to 6.2.5, there is a vulnerability in relative path traversal because it does not filter request path starting with './'. Successful exploitation could allow an remote unauthenticated attacker to access critical data, such as configuration files and deployed application source code.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:eclipse:glassfish:*:*:*:*:*:*:*:* 5.1.0 (including) 6.2.5 (including)


References to Advisories, Solutions, and Tools