Beveiligingsadvies

CVE-2024-9329

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2024-09-30 07:11:53
Laatst bijgewerkt 2024-10-07 15:59:12
Toegewezen door eclipse
CVSS-score 6.9
Status PUBLISHED

Beschrijving

In Eclipse Glassfish versions before 7.0.17, The Host HTTP parameter could cause the web application to redirect to the specified URL, when the requested endpoint is '/management/domain'. By modifying the URL value to a malicious site, an attacker may successfully launch a phishing scam and steal user credentials.