← Back

CVE-2024-7312

nvd nist
Published: Sep 11, 2024Modified: Jun 17, 2026

JSON object

Loading...
7.0
Vector
CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:A/VC:H/VI:H/VA:H/SC:N/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Show more
CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:A/VC:H/VI:H/VA:H/SC:N/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: 769c9ae7-73c3-4e47-ae19-903170fc3eb8 (Secondary)

Description

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Payara Platform Payara Server (REST Management Interface modules) allows Session Hijacking.This issue affects Payara Server: from 6.0.0 before 6.18.0, from 6.2022.1 before 6.2024.9, from 5.2020.2 before 5.2022.5, from 5.20.0 before 5.67.0, from 4.1.2.191.0 before 4.1.2.191.50.

Affected (5)

Products: Payara: Payara
1 product
Payara
Configuration A
5 vulnerable
Vulnerable SoftwareAffected Versions
Payara
From 4.1.2.191.0 to 4.1.2.191.50
From 5.2020.2 to 5.2022.5
From 6.2022.1 to 6.2024.9
From 5.20.0 to 5.67.0
From 6.0.0 to 6.18.0

References (2)

Timeline

No history available yet.