Описание
A flaw was found in WildFly Elytron. Password hashing and verification normalize input with Unicode NFKC, which can collapse fullwidth characters to ASCII equivalents. A remote attacker can more easily guess affected passwords by using an ASCII-only dictionary against accounts whose passwords were intended to include those non-ASCII characters, leading to unauthorized access.
Отчет
This issue has Moderate impact. Successful exploitation depends on accounts using fullwidth or other NFKC-compatibility characters in passwords and on the feasibility of password guessing against the deployed hash algorithm. Red Hat products that ship org.wildfly.security:wildfly-elytron-password-impl may be affected.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat build of Apache Camel 4 for Quarkus 3 | wildfly-elytron-password-impl | Affected | ||
| Red Hat build of Debezium 3 | wildfly-elytron-password-impl | Affected | ||
| Red Hat Build of Keycloak | keycloak/rhbk-openshift-rhel9 | Affected | ||
| Red Hat Build of Keycloak | wildfly-elytron-password-impl | Affected | ||
| Red Hat build of Quarkus | wildfly-elytron-password-impl | Affected | ||
| Red Hat Data Grid 8 | wildfly-elytron-password-impl | Affected | ||
| Red Hat JBoss Enterprise Application Platform 7 | jboss-eap-7/eap74-els-openjdk17-openshift-rhel8 | Will not fix | ||
| Red Hat JBoss Enterprise Application Platform 7 | jboss-eap-7/eap74-els-openjdk8-openshift-rhel8 | Will not fix | ||
| Red Hat JBoss Enterprise Application Platform 7 | wildfly-elytron-password-impl | Will not fix | ||
| Red Hat JBoss Enterprise Application Platform 8 | wildfly-elytron-password-impl | Affected |
Показывать по
Дополнительная информация
Статус:
EPSS
7.4 High
CVSS3
Связанные уязвимости
A flaw was found in WildFly Elytron. Password hashing and verification normalize input with Unicode NFKC, which can collapse fullwidth characters to ASCII equivalents. A remote attacker can more easily guess affected passwords by using an ASCII-only dictionary against accounts whose passwords were intended to include those non-ASCII characters, leading to unauthorized access.
A flaw was found in WildFly Elytron. Password hashing and verification normalize input with Unicode NFKC, which can collapse fullwidth characters to ASCII equivalents. A remote attacker can more easily guess affected passwords by using an ASCII-only dictionary against accounts whose passwords were intended to include those non-ASCII characters, leading to unauthorized access.
EPSS
7.4 High
CVSS3