Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qgrq-cx4c-2rmm

Опубликовано: 15 фев. 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Incorrect Authorization in WildFly Elytron

A flaw was found in all supported versions before wildfly-elytron-1.6.8.Final-redhat-00001, where the WildFlySecurityManager checks were bypassed when using custom security managers, resulting in an improper authorization. This flaw leads to information exposure by unauthenticated access to secure resources.

Пакеты

Наименование

org.wildfly.security:wildfly-elytron

maven
Затронутые версииВерсия исправления

<= 1.6.7

1.6.8

EPSS

Процентиль: 54%
0.0031
Низкий

7.5 High

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 4.8
redhat
больше 5 лет назад

A flaw was found in all supported versions before wildfly-elytron-1.6.8.Final-redhat-00001, where the WildFlySecurityManager checks were bypassed when using custom security managers, resulting in an improper authorization. This flaw leads to information exposure by unauthenticated access to secure resources.

CVSS3: 7.5
nvd
больше 5 лет назад

A flaw was found in all supported versions before wildfly-elytron-1.6.8.Final-redhat-00001, where the WildFlySecurityManager checks were bypassed when using custom security managers, resulting in an improper authorization. This flaw leads to information exposure by unauthenticated access to secure resources.

EPSS

Процентиль: 54%
0.0031
Низкий

7.5 High

CVSS3

Дефекты

CWE-863