GlassFish Security Fixes Summary

Vulnerability Severity Versions affected Fixed in version Summary
CVE-2024-9342 6.3 MEDIUM 7.0.16 - 7.0.25 8.0.3, 7.0.26 Eclipse GlassFish is vulnerable to Login Brute Force attacks through unlimited failed login attempts
CVE-2026-54512 8.1 HIGH 7.0.16 - 7.0.25, 7.1.0, 8.0.0 - 8.0.2 8.0.3, 7.1.1, 7.0.26 jackson-databind has a PolymorphicTypeValidator bypass via generic type parameters that allows arbitrary class instantiation
CVE-2026-54513 8.1 HIGH 7.0.16 - 7.0.25, 7.1.0, 8.0.0 - 8.0.2 8.0.3, 7.1.1, 7.0.26 jackson-databind has an array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray)
CVE-2026-54514 5.3 MEDIUM 7.0.16 - 7.0.25, 7.1.0, 8.0.0 - 8.0.2 8.0.3, 7.1.1, 7.0.26 jackson-databind: InetSocketAddress deserialization triggers eager DNS resolution (SSRF)
CVE-2026-54516 5.3 MEDIUM 8.0.0 - 8.0.2 8.0.3 jackson-databind's renamed @JsonIgnore'd setters can deserialize via private fields
CVE-2026-54517 5.3 MEDIUM 8.0.0 - 8.0.2 8.0.3 jackson-databind has @JsonView bypass for setterless creator properties
CVE-2026-54518 6.5 MEDIUM 8.0.0 - 8.0.2 8.0.3 jackson-databind has a @JsonView bypass for unwrapped creator parameters
CVE-2026-24457 9.8 CRITICAL < 8.0.2 8.0.2 9.8 CRITICAL - An unsafe parsing of OpenMQ's configuration, allows to read arbitrary files from a MQ Broker's server
CVE-2026-2586 9.1 CRITICAL 7.0.16 - 8.0.1 8.0.2, 7.1.1, 7.0.26 GlassFish's Administration Console is Vulnerable to RCE
CVE-2026-2587 9.6 CRITICAL 7.0.16 - 8.0.1 8.0.2, 7.1.1, 7.0.26 GlassFish's gadget handler is vulnerable to RCE
CVE-2020-27511 7.5 HIGH < 8.0.0 8.0.0, 7.1.1, 7.0.26 HIGH, 7.5 - Upgrade Woodstock to 6.0.3 with a security fix for prototype
CVE-2020-5258 7.7 HIGH < 8.0.0 8.0.0, 7.1.0, 7.0.26 HIGH, 7.7 - Upgrade dojo.js to 1.16.5
CVE-2024-10029 4.5 MEDIUM 7.0.16 - 7.0.25 7.0.26 Eclipse GlassFish is vulnerable to Reflected XSS attacks through its Administration Console
CVE-2024-10031 5.8 MEDIUM 7.0.16 - 7.0.25 7.0.26 Eclipse GlassFish is vulnerable to Stored XSS attacks through configuration file modifications
CVE-2024-10032 6.1 MEDIUM 7.0.16 - 7.0.25 7.0.26 Eclipse GlassFish is vulnerable to Stored XSS attacks through its Administration Console
CVE-2024-9343 6.1 MEDIUM 7.0.16 - 7.0.25 7.0.26 Eclipse GlassFish is vulnerable to Stored XSS attacks through its Administration Console
CVE-2025-12383 9.4 CRITICAL 7.0.20 - 7.0.21 7.0.22 Eclipse Jersey has a Race Condition
CVE-2024-9329 6.9 MEDIUM 7.0.16 7.0.17 Eclipse Glassfish improperly handles http parameters
CVE-2023-41080 6.1 MEDIUM < 7.0.10 7.0.10 Avoid protocol relative redirects in
CVE-2022-46337 9.8 CRITICAL Not impacted GlassFish not affected because bundled Derby DB does not authenticate database users via LDAP

Generated at: 2026-07-12 18:23:22

Scroll to Top