PT-2024-39578 · Eclipse · Eclipse Glassfish
Andrea Carlo Maria Dattola
+4
·
Published
2024-09-30
·
Updated
2024-10-07
·
CVE-2024-9329
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Eclipse Glassfish versions prior to 7.0.17
Description
The Host HTTP parameter could cause the web application to redirect to the specified URL when the requested endpoint is "/management/domain". By modifying the URL value to a malicious site, an attacker may successfully launch a phishing scam and steal user credentials.
Recommendations
For Eclipse Glassfish versions prior to 7.0.17, as a temporary workaround, consider restricting access to the "/management/domain" endpoint until a patch is available. Avoid using the Host HTTP parameter in the affected endpoint to minimize the risk of exploitation. Update to version 7.0.17 or later to resolve the issue.
Exploit
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Eclipse Glassfish