PT-2024-39578 · Eclipse · Eclipse Glassfish

Andrea Carlo Maria Dattola

+4

·

Published

2024-09-30

·

Updated

2024-10-07

·

CVE-2024-9329

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Eclipse Glassfish versions prior to 7.0.17
Description The Host HTTP parameter could cause the web application to redirect to the specified URL when the requested endpoint is "/management/domain". By modifying the URL value to a malicious site, an attacker may successfully launch a phishing scam and steal user credentials.
Recommendations For Eclipse Glassfish versions prior to 7.0.17, as a temporary workaround, consider restricting access to the "/management/domain" endpoint until a patch is available. Avoid using the Host HTTP parameter in the affected endpoint to minimize the risk of exploitation. Update to version 7.0.17 or later to resolve the issue.

Exploit

Fix

Open Redirect

Weakness Enumeration

Related Identifiers

CVE-2024-9329
GHSA-JQ3F-MFMG-747X

Affected Products

Eclipse Glassfish