Eclipse / Glassfish
13 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-12605 | In Eclipse GlassFish versions 8.0.x before 8.0.4, CSRF + SSRF in DownloadServlet ContentSources leaks the admin `gfresttoken` to attacker-controlled host if th… | CRITICAL | 9.6 | Aug 6, 2026 |
| CVE-2026-2586 | An authenticated Remote Code Execution (RCE) vulnerability was identified in GlassFish's Administration Console. A user with access to the panel can send craft… | CRITICAL | 9.1 | May 19, 2026 |
| CVE-2026-2587 | A critical Remote Code Execution (RCE) vulnerability was identified in the server-side template rendering mechanism used by the Glassfish gadget handler. The a… | CRITICAL | 9.6 | May 19, 2026 |
| CVE-2024-9408 | In Eclipse GlassFish since version 6.2.5 it is possible to perform a Server Side Request Forgery attack in specific endpoints. | HIGH | 8.9 | Jul 16, 2025 |
| CVE-2024-10032 | In Eclipse GlassFish version 7.0.15 is possible to perform Stored Cross-site scripting attacks in the Administration Console. | MEDIUM | 6.1 | Jul 16, 2025 |
| CVE-2024-10031 | In Eclipse GlassFish version 7.0.15 is possible to perform Stored Cross-site Scripting attacks by modifying the configuration file in the underlying operating… | MEDIUM | 5.8 | Jul 16, 2025 |
| CVE-2024-10029 | In Eclipse GlassFish version 7.0.15 is possible to perform Reflected Cross-site scripting attacks in the Administration Console. | MEDIUM | 4.5 | Jul 16, 2025 |
| CVE-2024-9343 | In Eclipse GlassFish version 7.0.15 is possible to perform Stored Cross-site scripting attacks in the Administration Console. | MEDIUM | 6.1 | Jul 16, 2025 |
| CVE-2024-9342 | In Eclipse GlassFish versions before 8.0.3 it is possible to perform Login Brute Force attacks as there is no limitation in the number of failed login attempts… | MEDIUM | 6.3 | Jul 16, 2025 |
| CVE-2024-9329 | Glassfish redirect to untrusted site | MEDIUM | 6.9 | Sep 30, 2024 |
| CVE-2024-8646 | Eclipse Glassfish: URL redirection vulnerability to untrusted sites | MEDIUM | 5.3 | Sep 11, 2024 |
| CVE-2023-5763 | Glassfish remote code execution | CRITICAL | 9.8 | Nov 3, 2023 |
| CVE-2022-2712 | In Eclipse GlassFish versions 5.1.0 to 6.2.5, there is a vulnerability in relative path traversal because it does not filter request path starting with './'. S… | HIGH | 7.5 | Jan 27, 2023 |
Showing 1 to 13 of 13 CVEs