{"id":"CVE-2022-2712","title":"In Eclipse GlassFish versions 5.1.0 to 6.2.5, there is a vulnerability in relative path traversal because it does not filter request path starting with './'","summary":"In Eclipse GlassFish versions 5.1.0 to 6.2.5, there is a vulnerability in relative path traversal because it does not filter request path starting with './'. Successful exploitation could allow an remote unauthenticated attacker to acces…","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","cwe":["CWE-22","CWE-22"],"vendor":"eclipse","product":"glassfish","affected":["glassfish >= 5.1.0, <= 6.2.5"],"published":"2023-01-27","updated":"2026-07-22","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2022-2712","references":[{"url":"https://bugs.eclipse.org/580502","label":"emo@eclipse.org"},{"url":"https://bugs.eclipse.org/580502","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.00935,"epssPercentile":0.58713,"ingestedAt":"2026-07-22T15:33:17.025Z","slug":"CVE-2022-2712","body":"## Overview\n\nIn Eclipse GlassFish versions 5.1.0 to 6.2.5, there is a vulnerability in relative path traversal because it does not filter request path starting with './'. Successful exploitation could allow an remote unauthenticated attacker to access critical data, such as configuration files and deployed application source code. This is fixed in GlassFish 7.0.0.\n\n## Affected\n\n- `glassfish >= 5.1.0, <= 6.2.5`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}