CVE-2024-7312

Severity CVSS v4.0:
Pending analysis
Type:
CWE-601 URL Redirection to Untrusted Site ('Open Redirect')
Publication date:
11/09/2024
Last modified:
13/09/2024

Description

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Payara Platform Payara Server (REST Management Interface modules) allows Session Hijacking.This issue affects Payara Server: from 6.0.0 before 6.18.0, from 6.2022.1 before 6.2024.9, from 5.2020.2 before 5.2022.5, from 5.20.0 before 5.67.0, from 4.1.2.191.0 before 4.1.2.191.50.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:payara:payara:*:*:*:*:community:*:*:* 4.1.2.191.0 (including) 4.1.2.191.50 (excluding)
cpe:2.3:a:payara:payara:*:*:*:*:enterprise:*:*:* 5.20.0 (including) 5.67.0 (excluding)
cpe:2.3:a:payara:payara:*:*:*:*:community:*:*:* 5.2020.2 (including) 5.2022.5 (excluding)
cpe:2.3:a:payara:payara:*:*:*:*:enterprise:*:*:* 6.0.0 (including) 6.18.0 (excluding)
cpe:2.3:a:payara:payara:*:*:*:*:community:*:*:* 6.2022.1 (including) 6.2024.9 (excluding)