VDB
Sign up
CRITICAL9.1

GHSA-96v6-hq43-x9h4

GlassFish's Administration Console is Vulnerable to RCE

Quick fix

GHSA-96v6-hq43-x9h4 — org.glassfish.main.admingui:console-common: upgrade to the fixed version with the command below.

# pom.xml: bump <version>8.0.2</version> for org.glassfish.main.admingui:console-common

Details

An authenticated Remote Code Execution (RCE) vulnerability was identified in GlassFish's Administration Console. A user with access to the panel can send crafted requests that allow the execution of arbitrary operating system commands with the privileges of the application service user.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/org.glassfish.main.admingui:console-common
Introduced in: 0Fixed in: 8.0.2
Fix# pom.xml: bump <version>8.0.2</version> for org.glassfish.main.admingui:console-common
Maven/org.glassfish.jsftemplating:jsftemplating
Introduced in: 0Fixed in: 4.2.0
Fix# pom.xml: bump <version>4.2.0</version> for org.glassfish.jsftemplating:jsftemplating

References