CVE-2024-9342
Last modified
CVE-2024-9342 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. In Eclipse GlassFish versions before 8.0.3 it is possible to perform Login Brute Force attacks as there is no limitation in the number of failed login attempts. GlassFish 8.0.3 adds automatic attack protection documented in https://glassfish.org/docs/latest/security-guide.html#brute-force-attack-protection .. EPSS estimates a 0.40% chance of exploitation in the next 30 days.
Description
In Eclipse GlassFish versions before 8.0.3 it is possible to perform Login Brute Force attacks as there is no limitation in the number of failed login attempts. GlassFish 8.0.3 adds automatic attack protection documented in https://glassfish.org/docs/latest/security-guide.html#brute-force-attack-protection .
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Eclipse | Glassfish | 7.0.16 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2024-9342?
How severe is CVE-2024-9342?
How do I fix CVE-2024-9342?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-9328A vulnerability was found in SourceCodester Advocate Office …9.8
- CVE-2024-9329In Eclipse Glassfish versions before 7.0.17, The Host HTTP p…6.1
- CVE-2024-9333Permissions bypass in M-Files Connector for Copilot before v…5.3
- CVE-2024-9334Use of Hard-coded Credentials, Storage of Sensitive Data in …8.2
- CVE-2024-9340A Denial of Service (DoS) vulnerability in zenml-io/zenml ve…7.5
- CVE-2024-9341A flaw was found in Go. When FIPS mode is enabled on a syste…8.2
- CVE-2024-9343In Eclipse GlassFish version 7.0.15 is possible to perform S…6.1
- CVE-2024-9344The BerqWP – Automated All-In-One PageSpeed Optimization Plu…6.1
- CVE-2024-9345The Product Delivery Date for WooCommerce – Lite plugin for …6.1
- CVE-2024-9346The Embed videos and respect privacy plugin for WordPress is…6.1
- CVE-2024-9347The The Ultimate WordPress Toolkit – WP Extended plugin for …6.1
- CVE-2024-9348Docker Desktop before v4.34.3 allows RCE via unsanitized Git…8.9
Are you affected by CVE-2024-9342?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
