Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p9xf-3rm3-qh2h

Опубликовано: 25 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.8

Описание

Wildfly-Core user account mismanagement

A flaw was found in Wildfly. An incorrect JBOSS_LOCAL_USER challenge location when using the elytron configuration may lead to JBOSS_LOCAL_USER access to all users on the machine. The highest threat from this vulnerability is to confidentiality, integrity, and availability. This flaw affects wildfly-core versions prior to 17.0.

Пакеты

Наименование

org.wildfly.core:wildfly-core-parent

maven
Затронутые версииВерсия исправления

< 17.0

17.0

EPSS

Процентиль: 12%
0.00039
Низкий

7.8 High

CVSS3

Дефекты

CWE-552

Связанные уязвимости

CVSS3: 7.8
redhat
больше 4 лет назад

A flaw was found in Wildfly. An incorrect JBOSS_LOCAL_USER challenge location when using the elytron configuration may lead to JBOSS_LOCAL_USER access to all users on the machine. The highest threat from this vulnerability is to confidentiality, integrity, and availability. This flaw affects wildfly-core versions prior to 17.0.

CVSS3: 7.8
nvd
больше 3 лет назад

A flaw was found in Wildfly. An incorrect JBOSS_LOCAL_USER challenge location when using the elytron configuration may lead to JBOSS_LOCAL_USER access to all users on the machine. The highest threat from this vulnerability is to confidentiality, integrity, and availability. This flaw affects wildfly-core versions prior to 17.0.

CVSS3: 7.8
debian
больше 3 лет назад

A flaw was found in Wildfly. An incorrect JBOSS_LOCAL_USER challenge l ...

EPSS

Процентиль: 12%
0.00039
Низкий

7.8 High

CVSS3

Дефекты

CWE-552