org.glassfish.main.admingui:console-common
Maven6 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.glassfish.main.admingui:console-commonpage 1 of 1
- CVE-2024-10029MEDIUMCVSS 6.1EG 6.12025-07-16
vulnerable: 3.1.2 ... 7.0.9 (58 versions)
In Eclipse GlassFish version 7.0.15 is possible to perform Reflected Cross-site scripting attacks in the Administration Console.
- CVE-2024-10031MEDIUMCVSS 5.4EG 5.42025-07-16
vulnerable: 3.1.2 ... 7.0.9 (58 versions)
In Eclipse GlassFish version 7.0.15 is possible to perform Stored Cross-site Scripting attacks by modifying the configuration file in the underlying operating system.
- CVE-2024-9342CRITICALCVSS 9.8EG 9.82025-07-16
vulnerable: 3.1.2 ... 7.0.9 (58 versions)
In Eclipse GlassFish versions before 8.0.3 it is possible to perform Login Brute Force attacks as there is no limitation in the number of failed login attempts. GlassFish 8.0.3 adds automatic attack protection documented in https://glassf…
- CVE-2024-9343MEDIUMCVSS 6.1EG 6.12025-07-16
vulnerable: 3.1.2 ... 7.0.9 (58 versions)
In Eclipse GlassFish version 7.0.15 is possible to perform Stored Cross-site scripting attacks in the Administration Console.
- CVE-2024-9408CRITICALCVSS 9.8EG 9.82025-07-16
vulnerable: 3.1.2 ... 6.2.5 (27 versions)
In Eclipse GlassFish since version 6.2.5 it is possible to perform a Server Side Request Forgery attack in specific endpoints.
- CVE-2026-2586CRITICALCVSS 9.1EG 9.1✓ Fixed in 8.0.22026-05-19
vulnerable: 3.1.2 ... 8.0.1 (83 versions)
An authenticated Remote Code Execution (RCE) vulnerability was identified in GlassFish's Administration Console. A user with access to the panel can send crafted requests that allow the execution of arbitrary operating system commands with…
Check whether org.glassfish.main.admingui:console-common is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.glassfish.main.admingui:console-common CVEs against the assets you own.
Start Free Scan →