CyberRota Analysis
AI-GeneratedEclipse GlassFish versions prior to 8.0.4 are vulnerable to a critical CSRF and SSRF attack in the DownloadServlet, which allows an attacker to leak the admin `gfresttoken` to a malicious host if the victim is authenticated in the Admin Console. This vulnerability enables an unauthenticated attacker to take over the Eclipse GlassFish domain until the token expires. Organizations using affected versions should prioritize immediate updates to mitigate this severe risk.
Original NVD Description
In Eclipse GlassFish versions 8.0.x before 8.0.4, CSRF + SSRF in DownloadServlet ContentSources leaks the admin `gfresttoken` to attacker-controlled host if the victim is authenticated into the Admin Console -\> full unauthenticated takeover of Eclipse GlassFish domain until the token expires.
Related CVEs
Other vulnerabilities affecting the same vendor(s)