Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-24330

Опубликовано: 29 июл. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

A flaw was found in wildfly-core. A remote attacker, authenticated as a 'deployer' account, can import and deploy a malicious archive file from an untrusted source. This is achieved by leveraging WildFly libraries to craft a Java project that allows an HTTP POST request to upload and deploy the malicious archive. This could lead to further exploitation, such as arbitrary file read vulnerabilities.

Отчет

This vulnerability is rated Moderate for Red Hat products as it requires an attacker to be authenticated as a 'deployer' account. An authenticated attacker could deploy a malicious archive, potentially leading to arbitrary file read vulnerabilities.

Меры по смягчению последствий

To mitigate this vulnerability, restrict access to the 'deployer' account to only authorized and trusted administrators. Implement strong authentication policies for this account and consider limiting its permissions to prevent the deployment of untrusted applications. Ensure that the WildFly management interfaces are not exposed to untrusted networks and that only verified and signed applications are permitted for deployment. If the 'deployer' role is not strictly necessary, consider disabling or removing it. Changes to WildFly configuration may require a service restart to take effect.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Fuse 7wildfly-core-securityFix deferred
Red Hat JBoss Enterprise Application Platform 7wildfly-core-securityFix deferred
Red Hat JBoss Enterprise Application Platform 8wildfly-core-securityAffected
Red Hat JBoss Enterprise Application Platform Expansion Packwildfly-core-securityFix deferred
Red Hat Process Automation 7wildfly-core-securityFix deferred
Red Hat Single Sign-On 7wildfly-core-securityFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-434
https://bugzilla.redhat.com/show_bug.cgi?id=2431939wildfly-core: WildFly: Arbitrary File Read via malicious archive deployment

EPSS

Процентиль: 22%
0.00297
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
nvd
4 дня назад

A flaw was found in wildfly-core. A remote attacker, authenticated as a 'deployer' account, can import and deploy a malicious archive file from an untrusted source. This is achieved by leveraging WildFly libraries to craft a Java project that allows an HTTP POST request to upload and deploy the malicious archive. This could lead to further exploitation, such as arbitrary file read vulnerabilities.

CVSS3: 6.5
debian
4 дня назад

A flaw was found in wildfly-core. A remote attacker, authenticated as ...

CVSS3: 6.5
github
4 дня назад

A flaw was found in wildfly-core. A remote attacker, authenticated as a 'deployer' account, can import and deploy a malicious archive file from an untrusted source. This is achieved by leveraging WildFly libraries to craft a Java project that allows an HTTP POST request to upload and deploy the malicious archive. This could lead to further exploitation, such as arbitrary file read vulnerabilities.

EPSS

Процентиль: 22%
0.00297
Низкий

6.5 Medium

CVSS3