In Eclipse GlassFish version 7.0.15, it is possible to perform Stored Cross-Site Scripting attacks through the Administration Console.
References:GSA_kwCzR0hTQS02Mmc5LTk5bTctdzh3ds4ABKM_
Eclipse GlassFish is vulnerable to Stored XSS attacks through its Administration Console
Affected Packages | Affected Versions | Fixed Versions | |
---|---|---|---|
maven:org.glassfish.main.admingui:console-cluster-plugin | <= 7.0.25 | No known fixed version | |
Affected Version RangesAll affected versions5.1.0, 6.0.0, 6.1.0, 6.2.0, 6.2.1, 6.2.2, 6.2.3, 6.2.4, 6.2.5, 7.0.0, 7.0.1, 7.0.2, 7.0.3, 7.0.4, 7.0.5, 7.0.6, 7.0.7, 7.0.8, 7.0.9, 7.0.10, 7.0.11, 7.0.12, 7.0.13, 7.0.14, 7.0.15, 7.0.16, 7.0.17, 7.0.18, 7.0.19, 7.0.20, 7.0.21, 7.0.22, 7.0.23, 7.0.24, 7.0.25 |