Description
A flaw was found in codeplex-codehaus. A directory traversal attack (also known as path traversal) aims to access files and directories stored outside the intended folder. By manipulating files with "dot-dot-slash (../)" sequences and their variations or by using absolute file paths, it may be possible to access arbitrary files and directories stored on the file system, including application source code, configuration, and other critical system files.
Remediation
References
https://access.redhat.com/errata/RHSA-2023:2135
https://access.redhat.com/errata/RHSA-2023:3906
https://access.redhat.com/security/cve/CVE-2022-4244
https://bugzilla.redhat.com/show_bug.cgi?id=2149841
Related Vulnerabilities
CVE-2022-1295 Vulnerability in maven package org.webjars.bowergithub.alvarotrigo:fullpage.js
CVE-2015-0254 Vulnerability in maven package jstl:jstl
CVE-2019-10797 Vulnerability in maven package org.wso2.transport.http:org.wso2.transport.http.netty
CVE-2020-9298 Vulnerability in maven package com.netflix.spinnaker.orca:orca-core
CVE-2019-18394 Vulnerability in maven package org.igniterealtime.openfire:parent