Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-325x-xm3p-mmv6

Опубликовано: 06 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 9.6

Описание

In Eclipse GlassFish versions 8.0.x before 8.0.4, CSRF + SSRF in DownloadServlet ContentSources leaks the admin gfresttoken to attacker-controlled host if the victim is authenticated into the Admin Console -> full unauthenticated takeover of Eclipse GlassFish domain until the token expires.

In Eclipse GlassFish versions 8.0.x before 8.0.4, CSRF + SSRF in DownloadServlet ContentSources leaks the admin gfresttoken to attacker-controlled host if the victim is authenticated into the Admin Console -> full unauthenticated takeover of Eclipse GlassFish domain until the token expires.

EPSS

Процентиль: 13%
0.00223
Низкий

9.6 Critical

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 9.6
nvd
5 дней назад

In Eclipse GlassFish versions 8.0.x before 8.0.4, CSRF + SSRF in DownloadServlet ContentSources leaks the admin `gfresttoken` to attacker-controlled host if the victim is authenticated into the Admin Console -\> full unauthenticated takeover of Eclipse GlassFish domain until the token expires.

EPSS

Процентиль: 13%
0.00223
Низкий

9.6 Critical

CVSS3

Дефекты

CWE-918