{"id":"CVE-2024-9329","aliases":["GHSA-jq3f-mfmg-747x"],"url":"https://o3.security/vulnerability/CVE-2024-9329","summary":"Glassfish redirect to untrusted site","details":"In Eclipse Glassfish versions before 7.0.17, The Host HTTP parameter could cause the web application to redirect to the specified URL, when the requested endpoint is '/management/domain'. By modifying the URL value to a malicious site, an attacker may successfully launch a phishing scam and steal user credentials.","published":"2024-09-30T07:11:53.688Z","modified":"2026-08-12T03:51:42.019651154Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":2,"affectedPackages":[{"ecosystem":"Maven","name":"org.glassfish.main.admin:rest-service","fixedVersion":"7.0.17"}],"fix":{"url":"https://github.com/eclipse-ee4j/glassfish/pull/25106","label":"eclipse-ee4j/glassfish#25106"},"references":[{"type":"WEB","url":"https://www.gruppotim.it/it/footer/red-team.html"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/9xxx/CVE-2024-9329.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-9329"},{"type":"REPORT","url":"https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/232"},{"type":"FIX","url":"https://github.com/eclipse-ee4j/glassfish/pull/25106"},{"type":"WEB","url":"https://github.com/eclipse-ee4j/glassfish/commit/6ca35eee2ba90a8108984b27bec33f9cc50cd83b"},{"type":"PACKAGE","url":"https://github.com/eclipse-ee4j/glassfish"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:42.019651154Z"}}