CRITICAL9.1
GHSA-96v6-hq43-x9h4
GlassFish's Administration Console is Vulnerable to RCE
Quick fix
GHSA-96v6-hq43-x9h4 — org.glassfish.main.admingui:console-common: upgrade to the fixed version with the command below.
# pom.xml: bump <version>8.0.2</version> for org.glassfish.main.admingui:console-commonDetails
An authenticated Remote Code Execution (RCE) vulnerability was identified in GlassFish's Administration Console. A user with access to the panel can send crafted requests that allow the execution of arbitrary operating system commands with the privileges of the application service user.
Are you affected?
Enter the version of the package you're using.
Affected packages
Maven/org.glassfish.main.admingui:console-common
Introduced in:
0Fixed in: 8.0.2Fix
# pom.xml: bump <version>8.0.2</version> for org.glassfish.main.admingui:console-commonMaven/org.glassfish.jsftemplating:jsftemplating
Introduced in:
0Fixed in: 4.2.0Fix
# pom.xml: bump <version>4.2.0</version> for org.glassfish.jsftemplating:jsftemplating