Impact
Eclipse Grizzly versions before 5.0.2 incorrectly parse the trailer section of malformed trailer headers, allowing an attacker to craft malicious HTTP requests that can be smuggled between legitimate requests. This flaw, identified as CWE-444, enables HTTP request smuggling against exposed GlassFish servers.
Affected Systems
Eclipse GlassFish deployments that use Eclipse Grizzly older than version 5.0.2 are affected. No specific sub‑versions beyond this threshold are listed.
Risk and Exploitability
The CVSS score is 6.3, indicating a medium impact, and the EPSS score is less than 1%, implying a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation would involve sending crafted HTTP requests containing malformed trailer headers to GlassFish servers. The description does not specify any privileged access requirement.
OpenCVE Enrichment