GHSA-h28c-453m-h9xm

Suggest an improvement
Source
https://github.com/advisories/GHSA-h28c-453m-h9xm
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/08/GHSA-h28c-453m-h9xm/GHSA-h28c-453m-h9xm.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-h28c-453m-h9xm
Aliases
  • CVE-2022-37422
Published
2022-08-19T00:00:20Z
Modified
2023-11-08T04:10:08.246120Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
Path Traversal in Payara
Details

Payara through 5.2022.2 allows directory traversal without authentication. This affects Payara Server, Payara Micro, and Payara Server Embedded.

Database specific
{
    "cwe_ids": [
        "CWE-22"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2022-08-30T20:20:37Z",
    "nvd_published_at": "2022-08-18T19:15:00Z",
    "severity": "HIGH"
}
References

Affected packages

Maven / fish.payara.api:payara-bom

Package

Name
fish.payara.api:payara-bom
View open source insights on deps.dev
Purl
pkg:maven/fish.payara.api/payara-bom

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.2022.3

Affected versions

5.*
5.194
5.201
5.2020.2
5.2020.3
5.2020.4
5.2020.5
5.2020.6
5.2020.7
5.2021.1
5.2021.2
5.2021.3
5.2021.4
5.2021.5
5.2021.6
5.2021.7
5.2021.8
5.2021.9
5.2021.10
5.2022.1
5.2022.2

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/08/GHSA-h28c-453m-h9xm/GHSA-h28c-453m-h9xm.json"