Back

HIGH

Codehaus-plexus: directory traversal

Published Sep 25, 2023

Description

A flaw was found in codeplex-codehaus. A directory traversal attack (also known as path traversal) aims to access files and directories stored outside the intended folder. By manipulating files with "dot-dot-slash (../)" sequences and their variations or by using absolute file paths, it may be possible to access arbitrary files and directories stored on the file system, including application source code, configuration, and other critical system files.

Affected products

Remediation

Red Hat statement

Red Hat Single Sign-On uses this package for testing purposes and is not delivered with the distribution. Hence not affected status.

Weaknesses (1)

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Sep 25, 2023
Updated Aug 3, 2024
Reserved Dec 1, 2022
CISA Vulnrichment
Updated May 3, 2024
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Dec 1, 2022
GHSA-G6PH-X5WF-G337