CVE-2024-8646

Severity CVSS v4.0:
Pending analysis
Type:
CWE-601 URL Redirection to Untrusted Site ('Open Redirect')
Publication date:
11/09/2024
Last modified:
18/09/2024

Description

In Eclipse Glassfish versions prior to 7.0.10, a URL redirection vulnerability to untrusted sites existed.<br /> This vulnerability is caused by the vulnerability (CVE-2023-41080) in the Apache code included in GlassFish.<br /> This vulnerability only affects applications that are explicitly deployed to the root context (&amp;#39;/&amp;#39;).

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:eclipse:glassfish:*:*:*:*:*:*:*:* 5.1.0 (including) 7.0.10 (excluding)