CVE-2026-12605

🟠 Łataj w tym tygodniu

CSRF i SSRF w Eclipse GlassFish umożliwiają przejęcie domeny przez ujawnienie tokena administratora.

CVSS
9.6
EPSS
0.2%
Exploit
none
Vendor
Opis źródłowy (NVD)

In Eclipse GlassFish versions 8.0.x before 8.0.4, CSRF + SSRF in DownloadServlet ContentSources leaks the admin `gfresttoken` to attacker-controlled host if the victim is authenticated into the Admin Console -\> full unauthenticated takeover of Eclipse GlassFish domain until the token expires.

ssrf Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS9.6
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.2%
Opublikowano (NVD)2026-08-06 14:16:20 UTC
Ostatnia modyfikacja (NVD)2026-08-06 16:16:36 UTC
Referencje