Vulnerabilities
VEX
CWE
ATT&CK
KEV Catalogs
All catalogs
RadioCSIRT
CISA
CIRCL
ENISA
Shadowserver
Previdian
Community
Sightings
Comments
Bundles
Organizations
Contributors
Statistics
Log in
About
Search term
Success
← All credits
https://gitlab.eclipse.org/evilgensec
1 vulnerability record and advisories credit this contributor.
CVE-2026-12605
In Eclipse GlassFish versions 8.0.x before 8.0.4, CSRF + SSRF in DownloadServlet ContentSources leaks the admin `gfresttoken` to attacker-controlled host if the victim is authenticated into the Admin Console -\> full unauthenticated takeover of Eclipse Gl