← Vulnerability feed

Vulnerability record · CVE-2022-4244 · published 25 September 2023

CVE-2022-4244: Codehaus-plexus plexus-utils path traversal vulnerability

CCodehaus Plexus · Plexus Utils

A flaw was found in codeplex-codehaus. A directory traversal attack (also known as path traversal) aims to access files and directories stored outside the intended folder. By manipulating files with "dot-dot-slash (../)" sequences and their variations or by using absolute file paths, it may be possible to access arbitrary files and directories stored on the file system, including application source code, configuration, and other critical system files.

7.5 CVSS 3.1 High EPSS 1.3% · top 29.7% CWE-22 · Path traversal
7.5CVSS 3.1 base score
1.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
8References
17 Jun 2026Last modified by NVD

Description

A flaw was found in codeplex-codehaus. A directory traversal attack (also known as path traversal) aims to access files and directories stored outside the intended folder. By manipulating files with "dot-dot-slash (../)" sequences and their variations or by using absolute file paths, it may be possible to access arbitrary files and directories stored on the file system, including application source code, configuration, and other critical system files.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-4244 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2023-44487HTTP/2 Rapid Reset stream cancellation denial of serviceThe HTTP/2 protocol permits a client to cancel many streams quickly, and the server's handling of those resets consumes disproportionate resources. T…KEVEPSS 100%analysed9.8CVE-2017-1000487Codehaus-plexus plexus-utils os command injection vulnerabilityPlexus-utils before 3.0.16 is vulnerable to command injection because it does not correctly process the contents of double quoted strings.EPSS 6.5%8.8CVE-2025-67030Codehaus-plexus plexus-utils path traversal vulnerabilityDirectory Traversal vulnerability in the extractFile method of org.codehaus.plexus.util.Expand in plexus-utils before 6d780b3378829318ba5c2d29547e001…EPSS 0.66%8.1CVE-2023-4853Quarkus incorrect authorization vulnerabilityA flaw was found in Quarkus where HTTP security policies are not sanitizing certain character permutations correctly when accepting requests, resulti…EPSS 1.4%7.5CVE-2024-7885Redhat build of apache camel - hawtio race condition vulnerabilityA vulnerability was found in Undertow where the ProxyProtocolReadListener reuses the same StringBuilder instance across multiple requests. This issue…EPSS 2.6%7.5CVE-2023-1108Redhat build of quarkus vulnerabilityA flaw was found in undertow. This issue makes achieving a denial of service possible due to an unexpected handshake status updated in SslConduit, wh…EPSS 1.8%7.5CVE-2022-4492Redhat build of quarkus server-side request forgery (ssrf) vulnerabilityThe undertow client is not checking the server identity presented by the server certificate in https connections. This is a compulsory step (at least…EPSS 0.60%7.5CVE-2022-1278Redhat wildfly insecure default initialization vulnerabilityA flaw was found in WildFly, where an attacker can see deployment names, endpoints, and any other data the trace payload may contain.EPSS 0.86%

Source: NIST National Vulnerability Database (record CVE-2022-4244), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.