Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-10683

Опубликовано: 02 мая 2018
Источник: redhat
CVSS3: 8.1
EPSS Низкий

Описание

An issue was discovered in WildFly 10.1.2.Final. In the case of a default installation without a security realm reference, an attacker can successfully access the server without authentication. NOTE: the Security Realms documentation in the product's Admin Guide indicates that "without a security realm reference" implies "effectively unsecured." The vendor explicitly supports these unsecured configurations because they have valid use cases during development

Отчет

Red Hat Product Security does not consider this issue to be a vulnerability. The default installation are by default secured and set to have an authentication mechanism in place. It is possible to explicitly remove the realm from the configuration files when needed. For example, in case there's need to run in single user mode for development use, ability to switch off security is desirable so the admin console can be accessed without the need for user accounts. There is adequate mechanism in place to secure the WildFly environment.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss Data Grid 7wildflyNot affected
Red Hat JBoss Enterprise Application Platform 7wildflyNot affected
Red Hat Single Sign-On 7wildflyNot affected
Red Hat Virtualization 4eap7-wildflyNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-306
https://bugzilla.redhat.com/show_bug.cgi?id=1636014wildfly: Missing authentication in edfault installation without a security realm reference

EPSS

Процентиль: 58%
0.00358
Низкий

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
nvd
больше 7 лет назад

An issue was discovered in WildFly 10.1.2.Final. In the case of a default installation without a security realm reference, an attacker can successfully access the server without authentication. NOTE: the Security Realms documentation in the product's Admin Guide indicates that "without a security realm reference" implies "effectively unsecured." The vendor explicitly supports these unsecured configurations because they have valid use cases during development

CVSS3: 9.8
debian
больше 7 лет назад

An issue was discovered in WildFly 10.1.2.Final. In the case of a defa ...

CVSS3: 9.8
github
больше 3 лет назад

** DISPUTED ** An issue was discovered in WildFly 10.1.2.Final. In the case of a default installation without a security realm reference, an attacker can successfully access the server without authentication. NOTE: the Security Realms documentation in the product's Admin Guide indicates that "without a security realm reference" implies "effectively unsecured." The vendor explicitly supports these unsecured configurations because they have valid use cases during development.

EPSS

Процентиль: 58%
0.00358
Низкий

8.1 High

CVSS3