Description
Payara through 5.2022.2 allows directory traversal without authentication. This affects Payara Server, Payara Micro, and Payara Server Embedded.
Remediation
References
https://blog.payara.fish/august-community-5-release
https://www.payara.fish/downloads/
Related Vulnerabilities
CVE-2023-37962 Vulnerability in maven package io.jenkins.plugins:benchmark-evaluator
CVE-2022-43396 Vulnerability in maven package org.apache.kylin:kylin-core-common
CVE-2023-46652 Vulnerability in maven package org.jenkins-ci.plugins:lambdatest-automation
CVE-2021-41303 Vulnerability in maven package org.apache.shiro:shiro-core
CVE-2023-34459 Vulnerability in npm package @openzeppelin/contracts