CVE-2022-2712

In Eclipse GlassFish versions 5.1.0 to 6.2.5, there is a vulnerability in relative path traversal because it does not filter request path starting with './'. Successful exploitation could allow an remote unauthenticated attacker to access critical data, such as configuration files and deployed application source code. This is fixed in GlassFish 7.0.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:eclipse:glassfish:*:*:*:*:*:*:*:*

History

22 Jul 2026, 15:16

Type Values Removed Values Added
Summary (en) In Eclipse GlassFish versions 5.1.0 to 6.2.5, there is a vulnerability in relative path traversal because it does not filter request path starting with './'. Successful exploitation could allow an remote unauthenticated attacker to access critical data, such as configuration files and deployed application source code. (en) In Eclipse GlassFish versions 5.1.0 to 6.2.5, there is a vulnerability in relative path traversal because it does not filter request path starting with './'. Successful exploitation could allow an remote unauthenticated attacker to access critical data, such as configuration files and deployed application source code. This is fixed in GlassFish 7.0.0.

21 Nov 2024, 07:01

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 7.5
v2 : unknown
v3 : 6.5
References () https://bugs.eclipse.org/580502 - () https://bugs.eclipse.org/580502 -

07 Nov 2023, 03:46

Type Values Removed Values Added
References (CONFIRM) https://bugs.eclipse.org/580502 - Permissions Required, Vendor Advisory () https://bugs.eclipse.org/580502 -

Information

Published : 2023-01-27 10:15

Updated : 2026-07-22 15:16


NVD link : CVE-2022-2712

Mitre link : CVE-2022-2712

CVE.ORG link : CVE-2022-2712


JSON object : View

Products Affected

eclipse

  • glassfish
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')