This vulnerability is caused by the vulnerability (CVE-2023-41080) in the Apache code included in GlassFish.
This vulnerability only affects applications that are explicitly deployed to the root context ('/').
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-2746 | In Eclipse Glassfish versions prior to 7.0.10, a URL redirection vulnerability to untrusted sites existed. This vulnerability is caused by the vulnerability (CVE-2023-41080) in the Apache code included in GlassFish. This vulnerability only affects applications that are explicitly deployed to the root context ('/'). |
Github GHSA |
GHSA-7gq2-vwq9-w8vw | Eclipse Glassfish URL redirection vulnerability |
Wed, 18 Sep 2024 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Eclipse
Eclipse glassfish |
|
| CPEs | cpe:2.3:a:eclipse:glassfish:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Eclipse
Eclipse glassfish |
Wed, 11 Sep 2024 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 11 Sep 2024 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Eclipse Glassfish versions prior to 7.0.10, a URL redirection vulnerability to untrusted sites existed. This vulnerability is caused by the vulnerability (CVE-2023-41080) in the Apache code included in GlassFish. This vulnerability only affects applications that are explicitly deployed to the root context ('/'). | |
| Title | Eclipse Glassfish: URL redirection vulnerability to untrusted sites | |
| Weaknesses | CWE-601 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: eclipse
Published:
Updated: 2024-09-11T13:40:06.290Z
Reserved: 2024-09-10T08:33:09.749Z
Link: CVE-2024-8646
Updated: 2024-09-11T13:40:02.229Z
Status : Analyzed
Published: 2024-09-11T14:15:14.307
Modified: 2024-09-18T20:20:51.643
Link: CVE-2024-8646
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA