ESAPI (The OWASP Enterprise Security API) is a free, open source, web application security control library. Prior to version 2.3.0.0, the default implementation of `Validator.getValidDirectoryPath(String, String, File, boolean)` may incorrectly treat the tested input string as a child of the specified parent directory. This potentially could allow control-flow bypass checks to be defeated if an attack can specify the entire string representing the 'input' path. This vulnerability is patched in release 2.3.0.0 of ESAPI. As a workaround, it is possible to write one's own implementation of the Validator interface. However, maintainers do not recommend this.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade libowasp-esapi-java | Jul 30, 2024 | Apr 25, 2022 |
| Oracle Weblogic | — | Apply the Patch Set Update (PSU) 34298772 for version 12.2.1.3.0.Apply the Patch Set Update (PSU) 34429365 for version 14.1.1.0.0.Apply the Patch Set Update (PSU) 34236279 for version 12.2.1.4.0. | Jul 25, 2022 | Apr 25, 2022 |
| Ubuntu | — | Upgrade libowasp-esapi-javaUpgrade libowasp-esapi-java (Ubuntu Pro)Upgrade libowasp-esapi-java-doc (Ubuntu Pro) | Apr 17, 2026 | Apr 25, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub