Advisory Database
  • Advisories
  • Dependency Scanning
  1. maven
  2. ›
  3. org.owasp.esapi/esapi
  4. ›
  5. CVE-2022-23457

CVE-2022-23457: Path traversal in the OWASP Enterprise Security API

April 27, 2022 (updated November 3, 2025)

The default implementation of Validator.getValidDirectoryPath(String, String, File, boolean) may incorrectly treat the tested input string as a child of the specified parent directory. This potentially could allow control-flow bypass checks to be defeated if an attack can specify the entire string representing the ‘input’ path.

References

  • github.com/ESAPI/esapi-java-legacy
  • github.com/ESAPI/esapi-java-legacy/blob/develop/documentation/GHSL-2022-008_The_OWASP_Enterprise_Security_API.md
  • github.com/ESAPI/esapi-java-legacy/blob/develop/documentation/esapi4java-core-2.3.0.0-release-notes.txt
  • github.com/ESAPI/esapi-java-legacy/commit/a0d67b75593878b1b6e39e2acc1773b3effedb2a
  • github.com/ESAPI/esapi-java-legacy/security/advisories/GHSA-8m5h-hrqm-pxm2
  • github.com/advisories/GHSA-8m5h-hrqm-pxm2
  • lists.debian.org/debian-lts-announce/2025/07/msg00010.html
  • nvd.nist.gov/vuln/detail/CVE-2022-23457
  • security.netapp.com/advisory/ntap-20230127-0014
  • securitylab.github.com/advisories/GHSL-2022-008_The_OWASP_Enterprise_Security_API
  • www.oracle.com/security-alerts/cpujul2022.html

Code Behaviors & Features

Detect and mitigate CVE-2022-23457 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 2.3.0.0

Fixed versions

  • 2.3.0.0

Solution

Upgrade to version 2.3.0.0 or above.

Impact 7.5 HIGH

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Learn more about CVSS

Weakness

  • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Source file

maven/org.owasp.esapi/esapi/CVE-2022-23457.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 10 Dec 2025 00:18:40 +0000.