CVE-2024-9329

Source
https://cve.org/CVERecord?id=CVE-2024-9329
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-9329.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-9329
Aliases
Published
2024-09-30T07:11:53.688Z
Modified
2026-07-15T01:48:57.225908930Z
Severity
  • 6.9 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Glassfish redirect to untrusted site
Details

In Eclipse Glassfish versions before 7.0.17, The Host HTTP parameter could cause the web application to redirect to the specified URL, when the requested endpoint is '/management/domain'. By modifying the URL value to a malicious site, an attacker may successfully launch a phishing scam and steal user credentials.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/9xxx/CVE-2024-9329.json",
    "cna_assigner": "eclipse",
    "cwe_ids": [
        "CWE-233"
    ]
}
References

Affected packages

Git / github.com/eclipse-ee4j/glassfish

Affected ranges

Type
GIT
Repo
https://github.com/eclipse-ee4j/glassfish
Events
Database specific
{
    "cpe": "cpe:2.3:a:eclipse:glassfish:*:*:*:*:*:*:*:*",
    "source": [
        "AFFECTED_FIELD",
        "CPE_RANGE"
    ],
    "extracted_events": [
        {
            "introduced": "5.1.0"
        },
        {
            "last_affected": "7.0.16"
        },
        {
            "introduced": "0"
        },
        {
            "fixed": "7.0.17"
        }
    ]
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-9329.json"