Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-8646


In Eclipse Glassfish versions prior to 7.0.10, a URL redirection vulnerability to untrusted sites existed. This vulnerability is caused by the vulnerability (CVE-2023-41080) in the Apache code included in GlassFish. This vulnerability only affects applications that are explicitly deployed to the root context ('/').


Published

2024-09-11T14:15:14.307

Last Modified

2024-09-18T20:20:51.643

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 6.1 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-601
  • Type: Primary
    CWE-601

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application eclipse glassfish < 7.0.10 Yes

References