CVE-2023-41699
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Payara Platform Payara Server, Micro and Embedded (Servlet Implementation modules) allows Redirect Access to Libraries.This issue affects Payara Server, Micro and Embedded: from 5.0.0…
Does this matter?
Lower severity and a low EPSS score (0.41%). Track it; it rarely justifies an emergency change on its own.
Description
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Payara Platform Payara Server, Micro and Embedded (Servlet Implementation modules) allows Redirect Access to Libraries.This issue affects Payara Server, Micro and Embedded: from 5.0.0 before 5.57.0, from 4.1.2.191 before 4.1.2.191.46, from 6.0.0 before 6.8.0, from 6.2023.1 before 6.2023.11.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.41% probability · 34th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-601
- Affected
- payara/payara
- Source
- 769c9ae7-73c3-4e47-ae19-903170fc3eb8
References
- https://docs.payara.fish/community/docs/Release%20Notes/Release%20Notes%206.2023.11.htmlRelease Notes
- https://docs.payara.fish/enterprise/docs/Release%20Notes/Release%20Notes%206.8.0.htmlRelease Notes
- https://docs.payara.fish/community/docs/Release%20Notes/Release%20Notes%206.2023.11.htmlRelease Notes
- https://docs.payara.fish/enterprise/docs/Release%20Notes/Release%20Notes%206.8.0.htmlRelease Notes
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.