GHSA-vqrm-83g6-pfv4

Suggest an improvement
Source
https://github.com/advisories/GHSA-vqrm-83g6-pfv4
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/07/GHSA-vqrm-83g6-pfv4/GHSA-vqrm-83g6-pfv4.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-vqrm-83g6-pfv4
Aliases
Published
2025-07-16T12:30:22Z
Modified
2025-07-18T15:57:23.170612Z
Severity
  • 4.5 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:A/VC:L/VI:L/VA:N/SC:H/SI:H/SA:N CVSS Calculator
Summary
Eclipse GlassFish is vulnerable to Reflected XSS attacks through its Administration Console
Details

In Eclipse GlassFish version 7.0.15, it is possible to perform Reflected Cross-Site Scripting attacks through the Administration Console.

Database specific
{
    "github_reviewed": true,
    "severity": "MODERATE",
    "github_reviewed_at": "2025-07-18T15:17:19Z",
    "cwe_ids": [
        "CWE-79"
    ],
    "nvd_published_at": "2025-07-16T11:15:22Z"
}
References

Affected packages

Maven / org.glassfish.main.admingui:console-common

Package

Name
org.glassfish.main.admingui:console-common
View open source insights on deps.dev
Purl
pkg:maven/org.glassfish.main.admingui/console-common

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
7.0.25

Affected versions

3.*

3.1.2
3.1.2.2

4.*

4.0-b33
4.0-b72
4.0-b90
4.0
4.1
4.1.1
4.1.2

5.*

5.0
5.0.1
5.1.0-RC1
5.1.0-RC2
5.1.0

6.*

6.0.0-M1
6.0.0-RC1
6.0.0-RC2
6.0.0-RC3
6.0.0-RC4
6.0.0
6.1.0
6.2.0
6.2.1
6.2.2
6.2.3
6.2.4
6.2.5

7.*

7.0.0-M1
7.0.0-M2
7.0.0-M3
7.0.0-M4
7.0.0-M10
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.0.8
7.0.9
7.0.10
7.0.11
7.0.12
7.0.13
7.0.14
7.0.15
7.0.16
7.0.17
7.0.18
7.0.19
7.0.20
7.0.21
7.0.22
7.0.23
7.0.24
7.0.25

Maven / org.glassfish.main.admingui:console-cluster-plugin

Package

Name
org.glassfish.main.admingui:console-cluster-plugin
View open source insights on deps.dev
Purl
pkg:maven/org.glassfish.main.admingui/console-cluster-plugin

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
7.0.25

Affected versions

3.*

3.1.2
3.1.2.2

4.*

4.0-b33
4.0-b72
4.0-b90
4.0
4.1
4.1.1
4.1.2

5.*

5.0
5.0.1
5.1.0-RC1
5.1.0-RC2
5.1.0

6.*

6.0.0-M1
6.0.0-RC1
6.0.0-RC2
6.0.0-RC3
6.0.0-RC4
6.0.0
6.1.0
6.2.0
6.2.1
6.2.2
6.2.3
6.2.4
6.2.5

7.*

7.0.0-M1
7.0.0-M2
7.0.0-M3
7.0.0-M4
7.0.0-M10
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.0.8
7.0.9
7.0.10
7.0.11
7.0.12
7.0.13
7.0.14
7.0.15
7.0.16
7.0.17
7.0.18
7.0.19
7.0.20
7.0.21
7.0.22
7.0.23
7.0.24
7.0.25