📦 Glassfish

by Eclipse

🔍 What is Glassfish?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-9408

CRITICAL CVSS 9.8 Jul 16, 2025

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in Eclipse GlassFish application server. Attackers can exploit specific endpoints to make the server send unauthorized requests to...

CVE-2024-9342

CRITICAL CVSS 9.8 Jul 16, 2025

CVE-2024-9342 allows attackers to perform unlimited brute-force login attempts against Eclipse GlassFish servers, potentially compromising administrator or user accounts. This affects all deployments ...

CVE-2024-10032

MEDIUM CVSS 5.4 Jul 16, 2025

This stored cross-site scripting (XSS) vulnerability in Eclipse GlassFish 7.0.15 allows attackers to inject malicious scripts into the administration console. When administrators view compromised page...

CVE-2024-10029

MEDIUM CVSS 6.1 Jul 16, 2025

This vulnerability allows attackers to perform reflected cross-site scripting (XSS) attacks in the Eclipse GlassFish Administration Console. Attackers can inject malicious scripts that execute in vict...

CVE-2024-9329

MEDIUM CVSS 6.1 Sep 30, 2024

This vulnerability in Eclipse Glassfish allows attackers to redirect users to malicious websites via manipulated HTTP Host parameters when accessing the '/management/domain' endpoint. This enables phi...