Eclipse Foundation Glassfish vulnerabilities
2 known vulnerabilities affecting eclipse_foundation/glassfish.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2024-9329MEDIUMCVSS 6.9≥ 5.1.0, ≤ 7.0.162024-09-30
CVE-2024-9329 [MEDIUM] CWE-233 CVE-2024-9329: In Eclipse Glassfish versions before 7.0.17, The Host HTTP parameter could cause the web application
In Eclipse Glassfish versions before 7.0.17, The Host HTTP parameter could cause the web application to redirect to the specified URL, when the requested endpoint is '/management/domain'. By modifying the URL value to a malicious site, an attacker may successfully launch a phishing scam and steal user credentials.
cvelistv5nvd
CVE-2023-5763CRITICALCVSS 9.8≥ 6.0.0, ≤ 6.2.5≥ 5.0, ≤ 5.12023-11-03
CVE-2023-5763 [CRITICAL] CWE-20 CVE-2023-5763: In Eclipse Glassfish 5 or 6, running with old versions of JDK (lower than 6u211, or < 7u201, or < 8u
In Eclipse Glassfish 5 or 6, running with old versions of JDK (lower than 6u211, or < 7u201, or < 8u191), allows remote attackers to load malicious code on the server via access to insecure ORB listeners.
cvelistv5nvd