---
id: CVE-2022-2712
title: >-
  In Eclipse GlassFish versions 5.1.0 to 6.2.5, there is a vulnerability in
  relative path traversal because it does not filter request path starting with
  './'
summary: >-
  In Eclipse GlassFish versions 5.1.0 to 6.2.5, there is a vulnerability in
  relative path traversal because it does not filter request path starting with
  './'. Successful exploitation could allow an remote unauthenticated attacker
  to acces…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'
cwe:
  - CWE-22
  - CWE-22
vendor: eclipse
product: glassfish
affected:
  - 'glassfish >= 5.1.0, <= 6.2.5'
published: '2023-01-27'
updated: '2026-07-22'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2022-2712'
references:
  - url: 'https://bugs.eclipse.org/580502'
    label: emo@eclipse.org
  - url: 'https://bugs.eclipse.org/580502'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00935
epssPercentile: 0.59087
ingestedAt: '2026-07-22T15:33:17.025Z'
---

## Overview

In Eclipse GlassFish versions 5.1.0 to 6.2.5, there is a vulnerability in relative path traversal because it does not filter request path starting with './'. Successful exploitation could allow an remote unauthenticated attacker to access critical data, such as configuration files and deployed application source code. This is fixed in GlassFish 7.0.0.

## Affected

- `glassfish >= 5.1.0, <= 6.2.5`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
