{"id":"CVE-2024-9342","aliases":["GHSA-99f7-hp6j-v6q4"],"url":"https://o3.security/vulnerability/CVE-2024-9342","summary":"Eclipse GlassFish is vulnerable to Login Brute Force attacks through unlimited failed login attempts","details":"In Eclipse GlassFish versions before 8.0.3 it is possible to perform Login Brute Force attacks as there is no limitation in the number of failed login attempts. GlassFish 8.0.3 adds automatic attack protection documented in  https://glassfish.org/docs/latest/security-guide.html#brute-force-attack-protection .","published":"2025-07-16T10:14:28.966Z","modified":"2026-07-15T01:49:02.949910270Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.glassfish.main.admingui:console-common","fixedVersion":null}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/9xxx/CVE-2024-9342.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-9342"},{"type":"REPORT","url":"https://gitlab.eclipse.org/security/cve-assignement/-/issues/33"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T01:49:02.949910270Z"}}