Loading
In Eclipse GlassFish versions 5.1.0 to 6.2.5, there is a vulnerability in relative path traversal because it does not filter request path starting with './'. Successful exploitation could allow an remote unauthenticated attacker to access critical data, such as configuration files and deployed application source code.
Use CWE-22, Eclipse vendor hub and Glassfish product page to widen CVE-2022-2712 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2024-9408, CVE-2024-9329 and CVE-2023-5763 for nearby disclosures in the same product family.