Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-48253 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Payara Platform Payara Server (REST Management Interface modules) allows Session Hijacking.This issue affects Payara Server: from 6.0.0 before 6.18.0, from 6.2022.1 before 6.2024.9, from 5.2020.2 before 5.2022.5, from 5.20.0 before 5.67.0, from 4.1.2.191.0 before 4.1.2.191.50. |
Fri, 13 Sep 2024 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:payara:payara:*:*:*:*:community:*:*:* | |
| Metrics |
cvssV3_1
|
cvssV3_1
|
Wed, 11 Sep 2024 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Wed, 11 Sep 2024 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 11 Sep 2024 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 11 Sep 2024 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Payara
Payara payara |
|
| CPEs | cpe:2.3:a:payara:payara:*:*:*:*:enterprise:*:*:* | |
| Vendors & Products |
Payara
Payara payara |
|
| Metrics |
ssvc
|
Wed, 11 Sep 2024 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Payara Platform Payara Server (REST Management Interface modules) allows Session Hijacking.This issue affects Payara Server: from 6.0.0 before 6.18.0, from 6.2022.1 before 6.2024.9, from 5.2020.2 before 5.2022.5, from 5.20.0 before 5.67.0, from 4.1.2.191.0 before 4.1.2.191.50. | |
| Title | REST Interface Link Redirection via Host parameter | |
| Weaknesses | CWE-601 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Payara
Published:
Updated: 2024-09-11T19:32:42.844Z
Reserved: 2024-07-30T20:07:31.604Z
Link: CVE-2024-7312
Updated: 2024-09-11T18:15:23.128Z
Status : Analyzed
Published: 2024-09-11T16:15:08.080
Modified: 2024-09-13T16:27:50.577
Link: CVE-2024-7312
OpenCVE Enrichment
No data.
EUVD