Vulnerabilities > Eclipse > Glassfish > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-09-30 CVE-2024-9329 Open Redirect vulnerability in Eclipse Glassfish
In Eclipse Glassfish versions before 7.0.17, The Host HTTP parameter could cause the web application to redirect to the specified URL, when the requested endpoint is '/management/domain'.
network
low complexity
eclipse CWE-601
6.1
2024-09-11 CVE-2024-8646 Open Redirect vulnerability in Eclipse Glassfish
In Eclipse Glassfish versions prior to 7.0.10, a URL redirection vulnerability to untrusted sites existed. This vulnerability is caused by the vulnerability (CVE-2023-41080) in the Apache code included in GlassFish. This vulnerability only affects applications that are explicitly deployed to the root context ('/').
network
low complexity
eclipse CWE-601
6.1