Lucene search

K
cvelistPayaraCVELIST:CVE-2024-7312
HistorySep 11, 2024 - 3:28 p.m.

CVE-2024-7312 REST Interface Link Redirection via Host parameter

2024-09-1115:28:43
CWE-601
Payara
www.cve.org
2
cve-2024-7312
rest interface
link redirection
host parameter
url redirection
untrusted site
payara platform
payara server
session hijacking
vulnerability
security issue

CVSS4

7

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

HIGH

User Interaction

ACTIVE

CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:A/VC:H/SC:N/VI:H/SI:H/VA:H/SA:H

EPSS

0.001

Percentile

17.7%

URL Redirection to Untrusted Site (‘Open Redirect’) vulnerability in Payara Platform Payara Server (REST Management Interface modules) allows Session Hijacking.This issue affects Payara Server: from 6.0.0 before 6.18.0, from 6.2022.1 before 6.2024.9, from 5.2020.2 before 5.2022.5, from 5.20.0 before 5.67.0, from 4.1.2.191.0 before 4.1.2.191.50.

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "modules": [
      "REST Management Interface"
    ],
    "product": "Payara Server",
    "vendor": "Payara Platform",
    "versions": [
      {
        "lessThan": "6.18.0",
        "status": "affected",
        "version": "6.0.0",
        "versionType": "semver"
      },
      {
        "lessThan": "6.2024.9",
        "status": "affected",
        "version": "6.2022.1",
        "versionType": "semver"
      },
      {
        "lessThan": "5.2022.5",
        "status": "affected",
        "version": "5.2020.2",
        "versionType": "semver"
      },
      {
        "lessThan": "5.67.0",
        "status": "affected",
        "version": "5.20.0",
        "versionType": "semver"
      },
      {
        "lessThan": "4.1.2.191.50",
        "status": "affected",
        "version": "4.1.2.191.0",
        "versionType": "custom"
      }
    ]
  }
]

CVSS4

7

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

HIGH

User Interaction

ACTIVE

CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:A/VC:H/SC:N/VI:H/SI:H/VA:H/SA:H

EPSS

0.001

Percentile

17.7%

Related for CVELIST:CVE-2024-7312