Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-3717

Опубликовано: 18 авг. 2021
Источник: redhat
CVSS3: 7.8
EPSS Низкий

Описание

A flaw was found in Wildfly. An incorrect JBOSS_LOCAL_USER challenge location when using the elytron configuration may lead to JBOSS_LOCAL_USER access to all users on the machine. The highest threat from this vulnerability is to confidentiality, integrity, and availability. This flaw affects wildfly-core versions prior to 17.0.

A flaw was found in Wildfly. An incorrect JBOSS_LOCAL_USER challenge location when using the elytron configuration may lead to JBOSS_LOCAL_USER access to all users on the machine. The highest threat from this vulnerability is to confidentiality, integrity, and availability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat AMQ Broker 7wildflyNot affected
Red Hat CodeReady Studio 12wildflyWill not fix
Red Hat Data Grid 8wildflyFix deferred
Red Hat Integration Camel K 1wildflyWill not fix
Red Hat Integration Camel Quarkus 1wildflyWill not fix
Red Hat Integration Service RegistrywildflyWill not fix
Red Hat JBoss Data Grid 7wildflyOut of support scope
Red Hat JBoss Data Virtualization 6jbossasOut of support scope
Red Hat JBoss Data Virtualization 6wildflyOut of support scope
Red Hat JBoss Enterprise Application Platform 5jbossasOut of support scope

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-552
https://bugzilla.redhat.com/show_bug.cgi?id=1991305wildfly: incorrect JBOSS_LOCAL_USER challenge location may lead to giving access to all the local users

EPSS

Процентиль: 12%
0.00039
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
nvd
больше 3 лет назад

A flaw was found in Wildfly. An incorrect JBOSS_LOCAL_USER challenge location when using the elytron configuration may lead to JBOSS_LOCAL_USER access to all users on the machine. The highest threat from this vulnerability is to confidentiality, integrity, and availability. This flaw affects wildfly-core versions prior to 17.0.

CVSS3: 7.8
debian
больше 3 лет назад

A flaw was found in Wildfly. An incorrect JBOSS_LOCAL_USER challenge l ...

CVSS3: 7.8
github
больше 3 лет назад

Wildfly-Core user account mismanagement

EPSS

Процентиль: 12%
0.00039
Низкий

7.8 High

CVSS3

Уязвимость CVE-2021-3717