Описание
A vulnerability was found in Wildfly’s management interface. Due to the lack of limitation of sockets for the management interface, it may be possible to cause a denial of service hitting the nofile limit as there is no possibility to configure or set a maximum number of connections.
Отчет
Red Hat rates this as a Low impact since this requires high privileges to jeopardize the system. The management interface is normally internal/local only and not exposed externally.
Меры по смягчению последствий
Currently there is no available mitigation for this vulnerability. Please make sure to perform updates as they become available.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Build of Keycloak | wildfly-domain-http | Not affected | ||
| Red Hat Data Grid 8 | wildfly-domain-http | Not affected | ||
| Red Hat Fuse 7 | wildfly-domain-http | Out of support scope | ||
| Red Hat JBoss Data Grid 7 | wildfly-domain-http | Out of support scope | ||
| Red Hat JBoss Enterprise Application Platform Expansion Pack | wildfly-domain-http | Not affected | ||
| Red Hat Process Automation 7 | wildfly-domain-http | Out of support scope | ||
| Red Hat Single Sign-On 7 | wildfly-domain-http | Fix deferred | ||
| Important: Red Hat JBoss Enterprise Application Platform 7.4.19 Security update | wildfly-domain-http | Fixed | RHSA-2024:8080 | 14.10.2024 |
| Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 | eap7-hal-console | Fixed | RHSA-2024:8076 | 14.10.2024 |
| Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 | eap7-hibernate-validator | Fixed | RHSA-2024:8076 | 14.10.2024 |
Показывать по
Дополнительная информация
Статус:
EPSS
4.1 Medium
CVSS3
Связанные уязвимости
A vulnerability was found in Wildfly’s management interface. Due to the lack of limitation of sockets for the management interface, it may be possible to cause a denial of service hitting the nofile limit as there is no possibility to configure or set a maximum number of connections.
A vulnerability was found in Wildfly\u2019s management interface. Due ...
EPSS
4.1 Medium
CVSS3