Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-7312

Опубликовано: 11 сент. 2024
Источник: redhat
CVSS3: 6.1
EPSS Низкий

Описание

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Payara Platform Payara Server (REST Management Interface modules) allows Session Hijacking.This issue affects Payara Server: from 6.0.0 before 6.18.0, from 6.2022.1 before 6.2024.9, from 5.2020.2 before 5.2022.5, from 5.20.0 before 5.67.0, from 4.1.2.191.0 before 4.1.2.191.50.

A flaw was found in the Payara Server REST Management Interface modules. This vulnerability allows session hijacking via URL redirection to an untrusted site.

Отчет

The Open Redirect vulnerability in the Payara Server REST Management Interface modules is classified as a moderate severity issue due to its reliance on additional exploit scenarios and the need for user interaction. While the vulnerability can potentially lead to session hijacking or phishing attacks, its impact is contingent upon an attacker successfully tricking a user into visiting a malicious URL. This reliance on user action, coupled with the necessity of additional contextual exploitation, reduces the immediate risk compared to more direct vulnerabilities. Additionally, the server-side exposure is mitigated by the inherent security measures of the Payara Server and the requirement for valid session tokens or authentication credentials.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss Data Grid 7fish.payara.arquillian/arquillian-payara-server-4-managedNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-601
https://bugzilla.redhat.com/show_bug.cgi?id=2311731payara: Open Redirect Vulnerability in Payara Server REST Management Interface

EPSS

Процентиль: 21%
0.00066
Низкий

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
nvd
больше 1 года назад

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Payara Platform Payara Server (REST Management Interface modules) allows Session Hijacking.This issue affects Payara Server: from 6.0.0 before 6.18.0, from 6.2022.1 before 6.2024.9, from 5.2020.2 before 5.2022.5, from 5.20.0 before 5.67.0, from 4.1.2.191.0 before 4.1.2.191.50.

CVSS3: 6.1
github
больше 1 года назад

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Payara Platform Payara Server (REST Management Interface modules) allows Session Hijacking.This issue affects Payara Server: from 6.0.0 before 6.18.0, from 6.2022.1 before 6.2024.9, from 5.2020.2 before 5.2022.5, from 5.20.0 before 5.67.0, from 4.1.2.191.0 before 4.1.2.191.50.

EPSS

Процентиль: 21%
0.00066
Низкий

6.1 Medium

CVSS3