CVE-2024-7312 HIGH

CVE-2024-7312: REST Interface Link Redirection via Host parameter

Vendor Payara Platform
Product Payara Server
Weakness CWE-601 · Open redirect
Published September 11, 2024
Last update September 11, 2024

CVSS base score

7.0/10
Attack vector Local
Attack complexity High
Privileges required High
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:A/VC:H/VI:H/VA:H/SC:N/SI:H/SA:H

What the vulnerability does

01Description

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Payara Platform Payara Server (REST Management Interface modules) allows Session Hijacking.This issue affects Payara Server: from 6.0.0 before 6.18.0, from 6.2022.1 before 6.2024.9, from 5.2020.2 before 5.2022.5, from 5.20.0 before 5.67.0, from 4.1.2.191.0 before 4.1.2.191.50.

Key dates

02Disclosure timeline

September 11, 2024 CVE published
September 11, 2024 Record updated