.. _vulnerabilityManagement_skip_registry_33x_CVE-2024-9329: CVE-2024-9329 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Data: 2024-10-09 Severity: Medium CVSS Score: 6.9 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N) Riferimenti: - `https://nvd.nist.gov/vuln/detail/CVE-2024-9329 `_ - `https://github.com/eclipse-ee4j/glassfish/pull/25106 `_ - `https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/232 `_ Libreria: org.glassfish.jaxb:* < 7.0.17 **Descrizione** In Eclipse Glassfish versions before 7.0.17, The Host HTTP parameter could cause the web application to redirect to the specified URL, when the requested endpoint is '/management/domain'. By modifying the URL value to a malicious site, an attacker may successfully launch a phishing scam and steal user credentials. **Falso Positivo per GovWay** L'application server glassfish non รจ tra quelli supportati da GovWay. Gli archivi jar 'org.glassfish.jaxb:\*' non vengono utilizzati nel progetto GovWay. Configuration File: `false-positive.xml `_