Critical severity9.8NVD Advisory· Published Jul 16, 2025· Updated Jun 18, 2026
CVE-2024-9342
CVE-2024-9342
Description
In Eclipse GlassFish versions before 8.0.3 it is possible to perform Login Brute Force attacks as there is no limitation in the number of failed login attempts. GlassFish 8.0.3 adds automatic attack protection documented in https://glassfish.org/docs/latest/security-guide.html#brute-force-attack-protection .
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.glassfish.main.admingui:console-commonMaven | <= 7.0.25 | — |
Affected products
3- Eclipse Foundation/Eclipse Glassfishv5Range: 7.0.16
Patches
Vulnerability mechanics
References
4- github.com/advisories/GHSA-99f7-hp6j-v6q4ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-9342ghsaADVISORY
- gitlab.eclipse.org/security/cve-assignement/-/issues/33nvdIssue TrackingWEB
- gitlab.eclipse.org/security/vulnerability-reports/-/issues/231ghsaWEB
News mentions
0No linked articles in our index yet.