Описание
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Payara Platform Payara Server (REST Management Interface modules) allows Session Hijacking.This issue affects Payara Server: from 6.0.0 before 6.18.0, from 6.2022.1 before 6.2024.9, from 5.2020.2 before 5.2022.5, from 5.20.0 before 5.67.0, from 4.1.2.191.0 before 4.1.2.191.50.
A flaw was found in the Payara Server REST Management Interface modules. This vulnerability allows session hijacking via URL redirection to an untrusted site.
Отчет
The Open Redirect vulnerability in the Payara Server REST Management Interface modules is classified as a moderate severity issue due to its reliance on additional exploit scenarios and the need for user interaction. While the vulnerability can potentially lead to session hijacking or phishing attacks, its impact is contingent upon an attacker successfully tricking a user into visiting a malicious URL. This reliance on user action, coupled with the necessity of additional contextual exploitation, reduces the immediate risk compared to more direct vulnerabilities. Additionally, the server-side exposure is mitigated by the inherent security measures of the Payara Server and the requirement for valid session tokens or authentication credentials.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat JBoss Data Grid 7 | fish.payara.arquillian/arquillian-payara-server-4-managed | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
6.1 Medium
CVSS3
Связанные уязвимости
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Payara Platform Payara Server (REST Management Interface modules) allows Session Hijacking.This issue affects Payara Server: from 6.0.0 before 6.18.0, from 6.2022.1 before 6.2024.9, from 5.2020.2 before 5.2022.5, from 5.20.0 before 5.67.0, from 4.1.2.191.0 before 4.1.2.191.50.
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Payara Platform Payara Server (REST Management Interface modules) allows Session Hijacking.This issue affects Payara Server: from 6.0.0 before 6.18.0, from 6.2022.1 before 6.2024.9, from 5.2020.2 before 5.2022.5, from 5.20.0 before 5.67.0, from 4.1.2.191.0 before 4.1.2.191.50.
EPSS
6.1 Medium
CVSS3