Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:35267
HistoryApr 27, 2022 - 8:06 a.m.

Path Traversal

2022-04-2708:06:05
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
15

0.003 Low

EPSS

Percentile

69.3%

org.owasp.esapi:esapi is vulnerable to path traversal. A remote authenticated user is able to break out of expected directory via a crafted input through getValidDirectoryPath function, because it may incorrectly treat the tested input string as a child of the specified parent directory.

0.003 Low

EPSS

Percentile

69.3%