glassfish

1 article
sort: new top best
clear filter
0 7/10

A researcher discovered an SSRF vulnerability in a Jira instance and escalated it to local file read by chaining it with an internal GlassFish server exploit using double-URL encoding to bypass path traversal protections and read /etc/passwd.

Zain Sabahat Alyssa Herrera Jira GlassFish HackerTarget CVE reference to GlassFish exploit-db/39241
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 22 hours ago · details