In Eclipse Glassfish versions prior to 7.0.10, a URL redirection vulnerability to untrusted sites existed. This vulnerability is caused by the vulnerability (CVE-2023-41080) in the Apache code included in GlassFish. This vulnerability only affects applications that are explicitly deployed to the root context ('/').
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
Link | Tags |
---|---|
https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/163 | broken link |
https://gitlab.eclipse.org/security/cve-assignement/-/issues/34 | vendor advisory |
https://github.com/eclipse-ee4j/glassfish/pull/24655 | patch |
https://glassfish.org/download | product |