VYPR

Maven package

org.glassfish.main.admingui/console-common

pkg:maven/org.glassfish.main.admingui/console-common

Vulnerabilities (5)

  • CVE-2024-9408CriJul 16, 2025
    affected <= 6.2.5

    In Eclipse GlassFish since version 6.2.5 it is possible to perform a Server Side Request Forgery attack in specific endpoints.

  • CVE-2024-9343MedJul 16, 2025
    affected <= 7.0.25

    In Eclipse GlassFish version 7.0.15 is possible to perform Stored Cross-site scripting attacks in the Administration Console.

  • CVE-2024-9342CriJul 16, 2025
    affected <= 7.0.25

    In Eclipse GlassFish versions before 8.0.3 it is possible to perform Login Brute Force attacks as there is no limitation in the number of failed login attempts. GlassFish 8.0.3 adds automatic attack protection documented in https://glassfish.org/docs/latest/security-guide.html#b

  • CVE-2024-10031MedJul 16, 2025
    affected <= 7.0.25

    In Eclipse GlassFish version 7.0.15 is possible to perform Stored Cross-site Scripting attacks by modifying the configuration file in the underlying operating system.

  • CVE-2024-10029MedJul 16, 2025
    affected <= 7.0.25

    In Eclipse GlassFish version 7.0.15 is possible to perform Reflected Cross-site scripting attacks in the Administration Console.