CVE Published: 30/09/2024 |
CVE Updated: 07/10/2024 |
CVE Year: 2024 Source: eclipse |
Vendor: Eclipse Foundation |
Product: Glassfish Status : PUBLISHED
CVE-2024-9329 Description
In Eclipse Glassfish versions before 7.0.17, The Host HTTP parameter could cause the web application to redirect to the specified URL, when the requested endpoint is \'/management/domain\'. By modifying the URL value to a malicious site, an attacker may successfully launch a phishing scam and steal user credentials.