{"id":"GHSA-q35w-85pq-rv3x","summary":"Payara, when deployed to the root context, allows attackers to visit META-INF and WEB-INF","details":"Payara before 2022-11-04, when deployed to the root context, allows attackers to visit META-INF and WEB-INF, a different vulnerability than CVE-2022-37422. This affects Payara Platform Community before 4.1.2.191.38, 5.x before 5.2022.4, and 6.x before 6.2022.1, and Payara Platform Enterprise before 5.45.0.","aliases":["CVE-2022-45129"],"modified":"2025-09-04T18:57:28.147499Z","published":"2022-11-10T12:01:03Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2025-09-04T18:23:53Z","nvd_published_at":"2022-11-10T06:15:00Z","cwe_ids":["CWE-552"],"severity":"HIGH"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-45129"},{"type":"WEB","url":"https://github.com/payara/Payara/issues/6136"},{"type":"WEB","url":"https://github.com/payara/Payara/commit/cccdfddeda71c78ae7b3179db5429e1bb8a56b2e"},{"type":"WEB","url":"https://blog.payara.fish/whats-new-in-the-november-2022-payara-platform-release"},{"type":"WEB","url":"https://docs.payara.fish/community/docs/6.2022.1/Release%20Notes/Release%20Notes%206.2022.1.html"},{"type":"WEB","url":"https://docs.payara.fish/community/docs/Release%20Notes/Release%20Notes%205.2022.4.html"},{"type":"WEB","url":"https://docs.payara.fish/enterprise/docs/Release%20Notes/Release%20Notes%205.45.0.html"},{"type":"PACKAGE","url":"https://github.com/payara/Payara"},{"type":"WEB","url":"https://github.com/payara/Payara/issues?q=FISH-6775"},{"type":"WEB","url":"http://packetstormsecurity.com/files/169864/Payara-Platform-Path-Traversal.html"},{"type":"WEB","url":"http://seclists.org/fulldisclosure/2022/Nov/11"}],"affected":[{"package":{"name":"fish.payara.distributions:payara","ecosystem":"Maven","purl":"pkg:maven/fish.payara.distributions/payara"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"6.2021.1.Alpha1"},{"fixed":"6.2022.2"}]}],"versions":["6.2021.1.Alpha1","6.2022.1","6.2022.1.Alpha2","6.2022.1.Alpha3","6.2022.1.Alpha4"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/11/GHSA-q35w-85pq-rv3x/GHSA-q35w-85pq-rv3x.json"}},{"package":{"name":"fish.payara.distributions:payara","ecosystem":"Maven","purl":"pkg:maven/fish.payara.distributions/payara"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.0.0.Alpha1"},{"fixed":"5.2022.5"}]}],"versions":["5.0.0.Alpha1","5.0.0.Alpha2","5.0.0.Alpha3","5.181","5.182","5.183","5.184","5.191","5.192","5.193","5.193.1","5.194","5.201","5.2020.2","5.2020.3","5.2020.4","5.2020.5","5.2020.6","5.2020.7","5.2021.1","5.2021.10","5.2021.2","5.2021.3","5.2021.4","5.2021.5","5.2021.6","5.2021.7","5.2021.8","5.2021.9","5.2022.1","5.2022.2","5.2022.3","5.2022.4"],"database_specific":{"last_known_affected_version_range":"\u003c 5.2022.2","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/11/GHSA-q35w-85pq-rv3x/GHSA-q35w-85pq-rv3x.json"}},{"package":{"name":"fish.payara.distributions:payara","ecosystem":"Maven","purl":"pkg:maven/fish.payara.distributions/payara"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"4.1.2.181"}]}],"versions":["4.1.1.161","4.1.1.161.1","4.1.1.162","4.1.1.163","4.1.1.164","4.1.1.171","4.1.1.171.0.1","4.1.1.171.1","4.1.2.172","4.1.2.173","4.1.2.174","4.1.2.181"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/11/GHSA-q35w-85pq-rv3x/GHSA-q35w-85pq-rv3x.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}