CVE-2023-41699: Payara

Medium severity, CVSS 6.1. EPSS: 0.4% chance of exploitation in the next 30 days.

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Payara Platform Payara Server, Micro and Embedded (Servlet Implementation modules) allows Redirect Access to Libraries.This issue affects Payara Server, Micro and Embedded: from 5.0.0 before 5.57.0, from 4.1.2.191 before 4.1.2.191.46, from 6.0.0 before 6.8.0, from 6.2023.1 before 6.2023.11.

Affected products

  • Payara Payara: from 4.1.2.191, before 4.1.2.191.46 (fixed in 4.1.2.191.46); from 5.0.0, before 5.57.0 (fixed in 5.57.0); from 6.0.0, before 6.8.0 (fixed in 6.8.0); from 6.2023.1, before 6.2023.11 (fixed in 6.2023.11)

Published 2023-11-15. Last modified 2026-06-17.