Description
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Payara Platform Payara Server (REST Management Interface modules) allows Session Hijacking.This issue affects Payara Server: from 6.0.0 before 6.18.0, from 6.2022.1 before 6.2024.9, from 5.2020.2 before 5.2022.5, from 5.20.0 before 5.67.0, from 4.1.2.191.0 before 4.1.2.191.50.
Problem types
CWE-601 URL Redirection to Untrusted Site ('Open Redirect')
Product status
6.0.0 (semver) before 6.18.0
6.2022.1 (semver) before 6.2024.9
5.2020.2 (semver) before 5.2022.5
5.20.0 (semver) before 5.67.0
4.1.2.191.0 (custom) before 4.1.2.191.50
Credits
Marco Ventura
Claudia Bartolini
Andrea Carlo Maria Dattola
Debora Esposito
Massimiliano Brolli
References
docs.payara.fish/.../Release Notes/Release Notes 5.67.0.html
docs.payara.fish/.../Release Notes/Release Notes 6.18.0.html