In Eclipse GlassFish versions before 8.0.3 it is possible to perform Login Brute Force attacks as there is no limitation in the number of failed login attempts. GlassFish 8.0.3 adds automatic attack protection documented in https://glassfish.org/docs/latest/security-guide.html#brute-force-attack-protection .
References
| Link | Resource |
|---|---|
| https://gitlab.eclipse.org/security/cve-assignement/-/issues/33 | Issue Tracking |
Configurations
History
No history.
Information
Published : 2025-07-16 11:15
Updated : 2026-06-18 14:17
NVD link : CVE-2024-9342
Mitre link : CVE-2024-9342
CVE.ORG link : CVE-2024-9342
JSON object : View
Products Affected
eclipse
- glassfish
CWE
CWE-307
Improper Restriction of Excessive Authentication Attempts
