Junglewise Threat Intelligence

CVE-2024-9342: Eclipse GlassFish improper restriction of login attempts

CVE-2024-9342 · Severity: critical · CVSS 9.8 · Published 2025-07-16

Technologies: org.glassfish.main.admingui:console-common (Maven), Eclipse Foundation GlassFish. Vendors: Maven, Eclipse Foundation.

Executive brief

Eclipse GlassFish, a popular application server for hosting Java-based web applications, lacks a mechanism to limit failed login attempts. This allows an attacker to repeatedly guess passwords for administrative or user accounts without being blocked. If successful, an attacker could gain full control over the server, access sensitive application data, or disrupt business operations.

Technical details

Eclipse GlassFish (multiple versions including 5.x, 6.x, 7.x, and 8.x prior to 8.0.3) is vulnerable to CWE-307: Improper Restriction of Excessive Authentication Attempts. The software does not implement a maximum threshold for failed login attempts, allowing an unauthenticated attacker with network access to perform automated brute-force or credential stuffing attacks. Successful exploitation can lead to unauthorized access to the administration console or user accounts, potentially resulting in full system compromise. The issue is addressed in GlassFish 8.0.3, which introduces automatic brute-force protection.

Affected products

  • Eclipse Foundation GlassFish < 8.0.3

Timeline

  • 2025-07-16: disclosed
  • 2025-07-16: advisory
  • 2025-07-16: patched: Fixed in version 8.0.3

References

Related threats