Medium severity6.1NVD Advisory· Published Sep 11, 2024· Updated Jun 17, 2026
CVE-2024-8646
CVE-2024-8646
Description
In Eclipse Glassfish versions prior to 7.0.10, a URL redirection vulnerability to untrusted sites existed. This vulnerability is caused by the vulnerability (CVE-2023-41080) in the Apache code included in GlassFish. This vulnerability only affects applications that are explicitly deployed to the root context ('/').
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.glassfish.main.web:web-coreMaven | < 7.0.10 | 7.0.10 |
Affected products
3- Eclipse Foundation/Eclipse Glassfishv5Range: 5.1.0
Patches
Vulnerability mechanics
References
7- github.com/eclipse-ee4j/glassfish/pull/24655nvdPatchWEB
- github.com/advisories/GHSA-7gq2-vwq9-w8vwghsaADVISORY
- gitlab.eclipse.org/security/cve-assignement/-/issues/34nvdVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2024-8646ghsaADVISORY
- github.com/eclipse-ee4j/glassfish/commit/06b80012761d07f6e40e40aa6b0133465b0bd145ghsaWEB
- gitlab.eclipse.org/security/vulnerability-reports/-/issues/163nvdBroken LinkWEB
- glassfish.org/downloadnvdProductWEB
News mentions
0No linked articles in our index yet.