Description
Payara before 2022-11-04, when deployed to the root context, allows attackers to visit META-INF and WEB-INF, a different vulnerability than CVE-2022-37422. This affects Payara Platform Community before 4.1.2.191.38, 5.x before 5.2022.4, and 6.x before 6.2022.1, and Payara Platform Enterprise before 5.45.0.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-48046 | Payara before 2022-11-04, when deployed to the root context, allows attackers to visit META-INF and WEB-INF, a different vulnerability than CVE-2022-37422. This affects Payara Platform Community before 4.1.2.191.38, 5.x before 5.2022.4, and 6.x before 6.2022.1, and Payara Platform Enterprise before 5.45.0. |
Github GHSA |
GHSA-q35w-85pq-rv3x | Payara, when deployed to the root context, allows attackers to visit META-INF and WEB-INF |
References
History
Fri, 02 May 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-05-01T13:42:02.196Z
Reserved: 2022-11-10T00:00:00.000Z
Link: CVE-2022-45129
Updated: 2024-08-03T14:01:31.594Z
Status : Modified
Published: 2022-11-10T06:15:13.813
Modified: 2026-06-17T05:09:24.650
Link: CVE-2022-45129
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-552
Files or Directories Accessible to External Parties
EUVD
Github GHSA