CVE-2024-9408: SSRF
In Eclipse GlassFish since version 6.2.5 it is possible to perform a Server Side Request Forgery attack in specific endpoints.
Other sources
In Eclipse GlassFish version 6.2.5, it is possible to perform a Server Side Request Forgery attack using specific endpoints.
— GitHub
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-9408?
CVE-2024-9408 has been classified as a medium severity vulnerability due to its potential to facilitate Server Side Request Forgery attacks.
How do I fix CVE-2024-9408?
To mitigate CVE-2024-9408, upgrade to Eclipse GlassFish version 6.2.6 or later where the vulnerability has been addressed.
What specific endpoints are affected by CVE-2024-9408?
CVE-2024-9408 affects specific endpoints within Eclipse GlassFish that handle requests without proper validation.
Can CVE-2024-9408 be exploited remotely?
Yes, CVE-2024-9408 can be exploited remotely by an attacker sending crafted requests to the affected server.
Who is affected by CVE-2024-9408?
Users of Eclipse GlassFish version 6.2.5 and below are affected by CVE-2024-9408 and should take action to secure their installations.