CVE-2024-7312: REST Interface Link Redirection via Host parameter
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Payara Platform Payara Server (REST Management Interface modules) allows Session Hijacking.This issue affects Payara Server: from 6.0.0 before 6.18.0, from 6.2022.1 before 6.2024.9, from 5.2020.2 before 5.2022.5, from 5.20.0 before 5.67.0, from 4.1.2.191.0 before 4.1.2.191.50.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-7312?
CVE-2024-7312 has a high severity rating due to its potential for session hijacking.
How do I fix CVE-2024-7312?
To fix CVE-2024-7312, upgrade to Payara Server version 6.18.0 or later, 5.2022.5 or later, or any patched version of the affected software.
What products are affected by CVE-2024-7312?
CVE-2024-7312 affects Payara Server versions from 6.0.0 before 6.18.0, 5.2020.2 before 5.2022.5, and others within specified version ranges.
What type of vulnerability is CVE-2024-7312?
CVE-2024-7312 is classified as a URL Redirection to Untrusted Site vulnerability, commonly referred to as an Open Redirect.
Can CVE-2024-7312 lead to any attacks?
Yes, CVE-2024-7312 can be exploited for session hijacking attacks, allowing an attacker to gain unauthorized access to user sessions.