Description
Payara before 2022-11-04, when deployed to the root context, allows attackers to visit META-INF and WEB-INF, a different vulnerability than CVE-2022-37422. This affects Payara Platform Community before 4.1.2.191.38, 5.x before 5.2022.4, and 6.x before 6.2022.1, and Payara Platform Enterprise before 5.45.0.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-48046 | Payara before 2022-11-04, when deployed to the root context, allows attackers to visit META-INF and WEB-INF, a different vulnerability than CVE-2022-37422. This affects Payara Platform Community before 4.1.2.191.38, 5.x before 5.2022.4, and 6.x before 6.2022.1, and Payara Platform Enterprise before 5.45.0. |
Github GHSA |
GHSA-q35w-85pq-rv3x | Payara, when deployed to the root context, allows attackers to visit META-INF and WEB-INF |
References
History
Fri, 02 May 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-05-01T13:42:02.196Z
Reserved: 2022-11-10T00:00:00.000Z
Link: CVE-2022-45129
Updated: 2024-08-03T14:01:31.594Z
Status : Modified
Published: 2022-11-10T06:15:13.813
Modified: 2025-05-01T14:15:33.720
Link: CVE-2022-45129
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA