Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-12605

Опубликовано: 06 авг. 2026
Источник: nvd
CVSS3: 9.6
EPSS Низкий

Описание

In Eclipse GlassFish versions 8.0.x before 8.0.4, CSRF + SSRF in DownloadServlet ContentSources leaks the admin gfresttoken to attacker-controlled host if the victim is authenticated into the Admin Console -> full unauthenticated takeover of Eclipse GlassFish domain until the token expires.

EPSS

Процентиль: 13%
0.00223
Низкий

9.6 Critical

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 9.6
github
5 дней назад

In Eclipse GlassFish versions 8.0.x before 8.0.4, CSRF + SSRF in DownloadServlet ContentSources leaks the admin `gfresttoken` to attacker-controlled host if the victim is authenticated into the Admin Console -\> full unauthenticated takeover of Eclipse GlassFish domain until the token expires.

EPSS

Процентиль: 13%
0.00223
Низкий

9.6 Critical

CVSS3

Дефекты

CWE-918