URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Payara Platform Payara Server (REST Management Interface modules) allows Session Hijacking.This issue affects Payara Server: from 6.0.0 before 6.18.0, from 6.2022.1 before 6.2024.9, from 5.2020.2 before 5.2022.5, from 5.20.0 before 5.67.0, from 4.1.2.191.0 before 4.1.2.191.50.
History

Fri, 13 Sep 2024 16:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:payara:payara:*:*:*:*:community:*:*:*
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Wed, 11 Sep 2024 21:45:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H'}

threat_severity

Moderate


Wed, 11 Sep 2024 20:30:00 +0000


Wed, 11 Sep 2024 19:45:00 +0000


Wed, 11 Sep 2024 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Payara
Payara payara
CPEs cpe:2.3:a:payara:payara:*:*:*:*:enterprise:*:*:*
Vendors & Products Payara
Payara payara
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 11 Sep 2024 15:30:00 +0000

Type Values Removed Values Added
Description URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Payara Platform Payara Server (REST Management Interface modules) allows Session Hijacking.This issue affects Payara Server: from 6.0.0 before 6.18.0, from 6.2022.1 before 6.2024.9, from 5.2020.2 before 5.2022.5, from 5.20.0 before 5.67.0, from 4.1.2.191.0 before 4.1.2.191.50.
Title REST Interface Link Redirection via Host parameter
Weaknesses CWE-601
References
Metrics cvssV4_0

{'score': 7, 'vector': 'CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:A/VC:H/VI:H/VA:H/SC:N/SI:H/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Payara

Published: 2024-09-11T15:28:43.452Z

Updated: 2024-09-11T19:32:42.844Z

Reserved: 2024-07-30T20:07:31.604Z

Link: CVE-2024-7312

cve-icon Vulnrichment

Updated: 2024-09-11T18:15:23.128Z

cve-icon NVD

Status : Analyzed

Published: 2024-09-11T16:15:08.080

Modified: 2024-09-13T16:27:50.577

Link: CVE-2024-7312

cve-icon Redhat

Severity : Moderate

Publid Date: 2024-09-11T16:15:08Z

Links: CVE-2024-7312 - Bugzilla