Impact
Eclipse GlassFish versions 8.0.x before 8.0.4 suffer a combination of CSRF and SSRF in the DownloadServlet for ContentSources, causing the admin gfresttoken to be sent to an attacker‑controlled host when the victim is logged into the Admin Console. The leaked token allows an attacker to authenticate and control the entire domain until it expires, leading to a full unauthenticated takeover of the GlassFish deployment.
Affected Systems
The vulnerability affects Eclipse Foundation’s Eclipse GlassFish product, specifically all 8.0.x releases older than 8.0.4.
Risk and Exploitability
The CVSS score is 9.6, indicating critically high severity. The EPSS score is not available, so the current probability of exploitation cannot be quantified. The vulnerability is not listed in CISA’s KEV catalog. Likely, an attacker must first get a user to be authenticated to the Admin Console and then exploit the CSRF/SSRF path to leak the gfresttoken; once the token is captured the attacker can take control of the entire domain until the token expires. The attack vector is inferred to be remote, via the web application, and requires web traffic manipulation.
OpenCVE Enrichment