CVE Database
/

CVE-2024-9329

Back to search

CVE-2024-9329

Published: Sep 30, 2024

Modified: Oct 7, 2024

PUBLISHED

Description

In Eclipse Glassfish versions before 7.0.17, The Host HTTP parameter could cause the web application to redirect to the specified URL, when the requested endpoint is '/management/domain'. By modifying the URL value to a malicious site, an attacker may successfully launch a phishing scam and steal user credentials.

VendorProductVersions

Eclipse Foundation

Glassfish

affected
5.1.0 - <= 7.0.16

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now