Description

In Eclipse Glassfish versions prior to 7.0.10, a URL redirection vulnerability to untrusted sites existed. This vulnerability is caused by the vulnerability (CVE-2023-41080) in the Apache code included in GlassFish. This vulnerability only affects applications that are explicitly deployed to the root context ('/').

INFO

Published Date :

2024-09-11T13:26:47.468Z

Last Modified :

2024-09-11T13:40:06.290Z

Source :

eclipse
AFFECTED PRODUCTS

The following products are affected by CVE-2024-8646 vulnerability.

Vendors Products
Eclipse
  • Glassfish

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact