PT-2025-29771 · Eclipse · Eclipse Glassfish

·

CVE-2024-9408

·

Published

2025-07-16

·

Updated

2025-07-16

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Eclipse GlassFish versions 6.2.5 and later
Description Eclipse GlassFish is susceptible to a Server Side Request Forgery (SSRF) attack affecting specific endpoints. SSRF occurs when an attacker can induce the server to make requests to unintended locations.
Recommendations Eclipse GlassFish versions 6.2.5 and later: Address the issue by restricting access to the affected endpoints.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-9408
GHSA-F7H5-C625-3795

Affected Products

Eclipse Glassfish