In Eclipse GlassFish versions before 8.0.3 it is possible to perform Login Brute Force attacks as there is no limitation in the number of failed login attempts. GlassFish 8.0.3 adds automatic attack protection documented in https://glassfish.org/docs/latest/security-guide.html#brute-force-attack-protection .
References
| Link | Resource |
|---|---|
| https://gitlab.eclipse.org/security/cve-assignement/-/issues/33 | Issue Tracking |
Configurations
History
18 Jun 2026, 14:17
| Type | Values Removed | Values Added |
|---|---|---|
| Summary | (en) In Eclipse GlassFish versions before 8.0.3 it is possible to perform Login Brute Force attacks as there is no limitation in the number of failed login attempts. GlassFish 8.0.3 adds automatic attack protection documented in https://glassfish.org/docs/latest/security-guide.html#brute-force-attack-protection . |
17 Jun 2026, 08:24
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
16 Jul 2025, 19:55
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://gitlab.eclipse.org/security/cve-assignement/-/issues/33 - Issue Tracking | |
| First Time |
Eclipse glassfish
Eclipse |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
| CPE | cpe:2.3:a:eclipse:glassfish:7.0.16:*:*:*:*:*:*:* |
16 Jul 2025, 11:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-07-16 11:15
Updated : 2026-06-18 14:17
NVD link : CVE-2024-9342
Mitre link : CVE-2024-9342
CVE.ORG link : CVE-2024-9342
JSON object : View
Products Affected
eclipse
- glassfish
CWE
CWE-307
Improper Restriction of Excessive Authentication Attempts
