CVE-2024-9342: Eclipse Glassfish
Critical severity, CVSS 9.8. EPSS: 0.4% chance of exploitation in the next 30 days.
In Eclipse GlassFish versions before 8.0.3 it is possible to perform Login Brute Force attacks as there is no limitation in the number of failed login attempts. GlassFish 8.0.3 adds automatic attack protection documented in https://glassfish.org/docs/latest/security-guide.html#brute-force-attack-protection .
Affected products
- Eclipse Glassfish: version 7.0.16 only
Published 2025-07-16. Last modified 2026-06-18.