Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-17614

Опубликовано: 04 авг. 2026
Источник: redhat
CVSS3: 4.4
EPSS Низкий

Описание

A path traversal flaw was found in WildFly's domain mode implementation. The LocalFileRepository.getFile() and getConfigurationFile() methods in wildfly-core/deployment-repository do not validate that the resolved file path remains within the configured repository or configuration root directories. A remote attacker who has obtained the slave host controller secret or compromised a slave host controller can supply a crafted relative path containing directory traversal sequences (e.g., ../../etc/passwd) via the slave-DC wire protocol, causing the Domain Controller to resolve and serve arbitrary files readable by the DC process. This leads to unauthorized disclosure of sensitive information such as configuration files, keystores, and system credentials.

Отчет

This Important vulnerability in WildFly domain mode allows an authenticated attacker, who has obtained the slave-secret credential, to perform arbitrary file reading on the Domain Controller's filesystem. This flaw bypasses intended access controls for file retrieval, potentially leading to sensitive information disclosure from the compromised host.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss Enterprise Application Platform 7eap74-els-openjdk11-openshift-rhel8/eap74-els-openjdk11-openshift-rhel8Fix deferred
Red Hat JBoss Enterprise Application Platform 7eap74-els-openjdk17-openshift-rhel8/eap74-els-openjdk17-openshift-rhel8Fix deferred
Red Hat JBoss Enterprise Application Platform 7eap74-els-openjdk8-openshift-rhel8/eap74-els-openjdk8-openshift-rhel8Fix deferred
Red Hat JBoss Enterprise Application Platform 7jboss-eap-7-eap74-els-openjdk17-openshift-rhel8/jboss-eap-7-eap74-els-openjdk17-openshift-rhel8Fix deferred
Red Hat JBoss Enterprise Application Platform 7jboss-eap-7-eap74-els-openjdk8-openshift-rhel8/jboss-eap-7-eap74-els-openjdk8-openshift-rhel8Fix deferred
Red Hat JBoss Enterprise Application Platform 7wildfly-deployment-repositoryFix deferred
Red Hat JBoss Enterprise Application Platform 8wildfly-deployment-repositoryAffected
Red Hat JBoss Enterprise Application Platform Expansion Packwildfly-deployment-repositoryFix deferred
Red Hat Single Sign-On 7wildfly-deployment-repositoryFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=2507631wildfly-core: Path Traversal on WildFly Domain Controller

EPSS

Процентиль: 55%
0.0085
Низкий

4.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.4
nvd
14 дней назад

A path traversal flaw was found in WildFly's domain mode implementation. The LocalFileRepository.getFile() and getConfigurationFile() methods in wildfly-core/deployment-repository do not validate that the resolved file path remains within the configured repository or configuration root directories. A remote attacker who has obtained the slave host controller secret or compromised a slave host controller can supply a crafted relative path containing directory traversal sequences (e.g., ../../etc/passwd) via the slave-DC wire protocol, causing the Domain Controller to resolve and serve arbitrary files readable by the DC process. This leads to unauthorized disclosure of sensitive information such as configuration files, keystores, and system credentials.

CVSS3: 4.4
debian
14 дней назад

A path traversal flaw was found in WildFly's domain mode implementat ...

CVSS3: 4.4
github
14 дней назад

A path traversal flaw was found in WildFly's domain mode implementation. The LocalFileRepository.getFile() and getConfigurationFile() methods in wildfly-core/deployment-repository do not validate that the resolved file path remains within the configured repository or configuration root directories. A remote attacker who has obtained the slave host controller secret or compromised a slave host controller can supply a crafted relative path containing directory traversal sequences (e.g., ../../etc/passwd) via the slave-DC wire protocol, causing the Domain Controller to resolve and serve arbitrary files readable by the DC process. This leads to unauthorized disclosure of sensitive information such as configuration files, keystores, and system credentials.

EPSS

Процентиль: 55%
0.0085
Низкий

4.4 Medium

CVSS3