Описание
A flaw was found in wildfly-core. A management user could use the resolve-expression in the HAL Interface to read possible sensitive information from the Wildfly system. This issue could allow a malicious user to access the system and obtain possible sensitive information from the system.
Отчет
This vulnerability requires a malicious user to previously have access to the system, especially access to the HAL interface via browser and logged with a management user who have access to the resolve-expression method, hence the moderate impact.
Меры по смягчению последствий
Wildfly administrators are recommended to use Vault, especially the Elytron subsystem, to store potential critical information such as DNS, IPs, and credentials.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat JBoss Enterprise Application Platform 8 | wildfly-core | Not affected | ||
| EAP 7.4.13 | wildfly-core | Fixed | RHSA-2023:5488 | 05.10.2023 |
| Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 | eap7-wildfly | Fixed | RHSA-2023:5485 | 06.10.2023 |
| Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 | eap7-wildfly-elytron | Fixed | RHSA-2023:5485 | 06.10.2023 |
| Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 | eap7-wildfly | Fixed | RHSA-2023:5486 | 06.10.2023 |
| Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 | eap7-wildfly-elytron | Fixed | RHSA-2023:5486 | 06.10.2023 |
| Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7 | eap7-wildfly | Fixed | RHSA-2023:5484 | 05.10.2023 |
| Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7 | eap7-wildfly-elytron | Fixed | RHSA-2023:5484 | 05.10.2023 |
Показывать по
Дополнительная информация
Статус:
6.5 Medium
CVSS3
Связанные уязвимости
A flaw was found in wildfly-core. A management user could use the resolve-expression in the HAL Interface to read possible sensitive information from the Wildfly system. This issue could allow a malicious user to access the system and obtain possible sensitive information from the system.
wildfly-core Exposure of Sensitive Information to an Unauthorized Actor vulnerability
6.5 Medium
CVSS3