PT-2018-10050 · Red Hat · Wildfly
Bourbon Jean-Marie
+3
·
Published
2018-05-09
·
Updated
2024-08-05
·
CVE-2018-10682
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
WildFly version 10.1.2.Final
Description
An issue allows an attacker to access the administration panel without authentication using
anonymous access. Once logged in, a misconfiguration permits an anonymous user to deploy a malicious .war file, leading to remote code execution. The vendor notes that anonymous access is not available by default but remains optional for certain use cases, such as development environments.Recommendations
For WildFly version 10.1.2.Final, consider disabling the anonymous access feature to prevent unauthorized access to the administration panel. Additionally, review and adjust the auto-deployment configuration to prevent malicious file deployments.
Exploit
Fix
RCE
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wildfly