Eclipse GlassFish是美国Eclipse基金会开源的一款应用服务器中间件。 Eclipse GlassFish 8.0.4版本之前的8.0.x版本存在服务端请求伪造漏洞,该漏洞源于DownloadServlet ContentSources存在跨站请求伪造和服务端请求伪造,可能导致管理员gfresttoken泄露至攻击者控制的主机,若受害者已登录管理控制台,攻击者可完全接管Eclipse GlassFish域。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Eclipse Foundation | Eclipse GlassFish | 8.0.0< 8.0.4 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Eclipse Foundation | Eclipse GlassFish | 8.0.0 ~ 8.0.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet