Maven package
org.glassfish.main.admingui/console-common
pkg:maven/org.glassfish.main.admingui/console-common
Vulnerabilities (5)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2024-9408 | Cri | 9.8 | <= 6.2.5 | — | Jul 16, 2025 | In Eclipse GlassFish since version 6.2.5 it is possible to perform a Server Side Request Forgery attack in specific endpoints. | |
| CVE-2024-9343 | Med | 6.1 | <= 7.0.25 | — | Jul 16, 2025 | In Eclipse GlassFish version 7.0.15 is possible to perform Stored Cross-site scripting attacks in the Administration Console. | |
| CVE-2024-9342 | Cri | 9.8 | <= 7.0.25 | — | Jul 16, 2025 | In Eclipse GlassFish versions before 8.0.3 it is possible to perform Login Brute Force attacks as there is no limitation in the number of failed login attempts. GlassFish 8.0.3 adds automatic attack protection documented in https://glassfish.org/docs/latest/security-guide.html#b | |
| CVE-2024-10031 | Med | 5.4 | <= 7.0.25 | — | Jul 16, 2025 | In Eclipse GlassFish version 7.0.15 is possible to perform Stored Cross-site Scripting attacks by modifying the configuration file in the underlying operating system. | |
| CVE-2024-10029 | Med | 6.1 | <= 7.0.25 | — | Jul 16, 2025 | In Eclipse GlassFish version 7.0.15 is possible to perform Reflected Cross-site scripting attacks in the Administration Console. |
- affected <= 6.2.5
In Eclipse GlassFish since version 6.2.5 it is possible to perform a Server Side Request Forgery attack in specific endpoints.
- affected <= 7.0.25
In Eclipse GlassFish version 7.0.15 is possible to perform Stored Cross-site scripting attacks in the Administration Console.
- affected <= 7.0.25
In Eclipse GlassFish versions before 8.0.3 it is possible to perform Login Brute Force attacks as there is no limitation in the number of failed login attempts. GlassFish 8.0.3 adds automatic attack protection documented in https://glassfish.org/docs/latest/security-guide.html#b
- affected <= 7.0.25
In Eclipse GlassFish version 7.0.15 is possible to perform Stored Cross-site Scripting attacks by modifying the configuration file in the underlying operating system.
- affected <= 7.0.25
In Eclipse GlassFish version 7.0.15 is possible to perform Reflected Cross-site scripting attacks in the Administration Console.