CVE-2024-8646: Eclipse Glassfish: URL redirection vulnerability to untrusted sites
In Eclipse Glassfish versions prior to 7.0.10, a URL redirection vulnerability to untrusted sites existed. This vulnerability is caused by the vulnerability (CVE-2023-41080) in the Apache code included in GlassFish. This vulnerability only affects applications that are explicitly deployed to the root context ('/').
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2024-8646?
CVE-2024-8646 is classified as a medium severity vulnerability due to its potential for URL redirection to untrusted sites.
How do I fix CVE-2024-8646?
To mitigate the CVE-2024-8646 vulnerability, upgrade Eclipse Glassfish to version 7.0.10 or later.
Which versions of Eclipse Glassfish are affected by CVE-2024-8646?
Eclipse Glassfish versions prior to 7.0.10 are affected by CVE-2024-8646.
What causes the vulnerability CVE-2024-8646?
CVE-2024-8646 is caused by a URL redirection vulnerability that stems from an issue in the Apache code integrated into GlassFish.
Is CVE-2024-8646 related to any other vulnerabilities?
Yes, CVE-2024-8646 is related to CVE-2023-41080, which contributes to the URL redirection issue.