Описание
A flaw was found in wildfly-core. A remote attacker, authenticated as a 'deployer' account, can import and deploy a malicious archive file from an untrusted source. This is achieved by leveraging WildFly libraries to craft a Java project that allows an HTTP POST request to upload and deploy the malicious archive. This could lead to further exploitation, such as arbitrary file read vulnerabilities.
Отчет
This vulnerability is rated Moderate for Red Hat products as it requires an attacker to be authenticated as a 'deployer' account. An authenticated attacker could deploy a malicious archive, potentially leading to arbitrary file read vulnerabilities.
Меры по смягчению последствий
To mitigate this vulnerability, restrict access to the 'deployer' account to only authorized and trusted administrators. Implement strong authentication policies for this account and consider limiting its permissions to prevent the deployment of untrusted applications. Ensure that the WildFly management interfaces are not exposed to untrusted networks and that only verified and signed applications are permitted for deployment. If the 'deployer' role is not strictly necessary, consider disabling or removing it. Changes to WildFly configuration may require a service restart to take effect.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Fuse 7 | wildfly-core-security | Fix deferred | ||
| Red Hat JBoss Enterprise Application Platform 7 | wildfly-core-security | Fix deferred | ||
| Red Hat JBoss Enterprise Application Platform 8 | wildfly-core-security | Affected | ||
| Red Hat JBoss Enterprise Application Platform Expansion Pack | wildfly-core-security | Fix deferred | ||
| Red Hat Process Automation 7 | wildfly-core-security | Fix deferred | ||
| Red Hat Single Sign-On 7 | wildfly-core-security | Fix deferred |
Показывать по
Дополнительная информация
Статус:
EPSS
6.5 Medium
CVSS3
Связанные уязвимости
A flaw was found in wildfly-core. A remote attacker, authenticated as a 'deployer' account, can import and deploy a malicious archive file from an untrusted source. This is achieved by leveraging WildFly libraries to craft a Java project that allows an HTTP POST request to upload and deploy the malicious archive. This could lead to further exploitation, such as arbitrary file read vulnerabilities.
A flaw was found in wildfly-core. A remote attacker, authenticated as ...
A flaw was found in wildfly-core. A remote attacker, authenticated as a 'deployer' account, can import and deploy a malicious archive file from an untrusted source. This is achieved by leveraging WildFly libraries to craft a Java project that allows an HTTP POST request to upload and deploy the malicious archive. This could lead to further exploitation, such as arbitrary file read vulnerabilities.
EPSS
6.5 Medium
CVSS3