PT-2025-29771 · Eclipse · Eclipse Glassfish

Mustafa Gündoğdu

·

Published

2025-07-16

·

Updated

2025-07-16

·

CVE-2024-9408

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Eclipse GlassFish versions 6.2.5 and later
Description Eclipse GlassFish is susceptible to a Server Side Request Forgery (SSRF) attack affecting specific endpoints. SSRF occurs when an attacker can induce the server to make requests to unintended locations.
Recommendations Eclipse GlassFish versions 6.2.5 and later: Address the issue by restricting access to the affected endpoints.

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2024-9408
GHSA-F7H5-C625-3795

Affected Products

Eclipse Glassfish