Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-20250

Опубликовано: 17 фев. 2021
Источник: redhat
CVSS3: 4.3

Описание

A flaw was found in wildfly. The JBoss EJB client has publicly accessible privileged actions which may lead to information disclosure on the server it is deployed on. The highest threat from this vulnerability is to data confidentiality.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Decision Manager 7jboss-ejb-clientNot affected
Red Hat Fuse 7jboss-ejb-clientNot affected
Red Hat JBoss Data Grid 7jboss-ejb-clientOut of support scope
Red Hat JBoss Enterprise Application Platform 6jboss-ejb-clientOut of support scope
Red Hat JBoss Fuse 6jboss-ejb-clientOut of support scope
Red Hat JBoss Fuse Service Works 6jboss-ejb-clientOut of support scope
Red Hat JBoss Operations Network 3jboss-ejb-clientOut of support scope
Red Hat OpenShift Application Runtimesjboss-ejb-clientNot affected
Red Hat Process Automation 7jboss-ejb-clientNot affected
Red Hat EAP-XP 2.0.0 via EAP 7.3.x basejboss-ejb-clientFixedRHSA-2021:275515.07.2021

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=1929479wildfly: Information disclosure due to publicly accessible privileged actions in JBoss EJB Client

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
nvd
около 4 лет назад

A flaw was found in wildfly. The JBoss EJB client has publicly accessible privileged actions which may lead to information disclosure on the server it is deployed on. The highest threat from this vulnerability is to data confidentiality.

CVSS3: 4.3
debian
около 4 лет назад

A flaw was found in wildfly. The JBoss EJB client has publicly accessi ...

CVSS3: 4.3
github
около 3 лет назад

JBoss EJB Client information disclosure vulnerability

4.3 Medium

CVSS3