Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-4503

Опубликовано: 04 дек. 2023
Источник: redhat
CVSS3: 6.8
EPSS Низкий

Описание

An improper initialization vulnerability was found in Galleon. When using Galleon to provision custom EAP or EAP-XP servers, the servers are created unsecured. This issue could allow an attacker to access remote HTTP services available from the server.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss Enterprise Application Platform Expansion Packeap-galleonAffected
EAP 7.4.14eap-galleonFixedRHSA-2023:764104.12.2023
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8eap7-undertowFixedRHSA-2023:763804.12.2023
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8eap7-wildflyFixedRHSA-2023:763804.12.2023
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9eap7-undertowFixedRHSA-2023:763904.12.2023
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9eap7-wildflyFixedRHSA-2023:763904.12.2023
Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7eap7-undertowFixedRHSA-2023:763704.12.2023
Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7eap7-wildflyFixedRHSA-2023:763704.12.2023
Red Hat JBoss Enterprise Application Platform 8FixedRHSA-2024:358304.06.2024
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8eap8-activemq-artemisFixedRHSA-2024:358004.06.2024

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-665
https://bugzilla.redhat.com/show_bug.cgi?id=2184751eap-galleon: custom provisioning creates unsecured http-invoker

EPSS

Процентиль: 41%
0.00191
Низкий

6.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.8
nvd
около 2 лет назад

An improper initialization vulnerability was found in Galleon. When using Galleon to provision custom EAP or EAP-XP servers, the servers are created unsecured. This issue could allow an attacker to access remote HTTP services available from the server.

CVSS3: 6.8
github
около 2 лет назад

An improper initialization vulnerability was found in Galleon. When using Galleon to provision custom EAP or EAP-XP servers, the servers are created unsecured. This issue could allow an attacker to access remote HTTP services available from the server.

EPSS

Процентиль: 41%
0.00191
Низкий

6.8 Medium

CVSS3