PT-2021-3878 · Red Hat · Wildfly Elytron
Guilherme De Almeida Suckevicz
·
Published
2021-06-30
·
Updated
2022-05-24
·
CVE-2021-3642
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Wildfly Elytron versions prior to 1.10.14.Final
Wildfly Elytron versions prior to 1.15.5.Final
Wildfly Elytron versions prior to 1.16.1.Final
Description
A flaw was found in Wildfly Elytron where ScramServer may be susceptible to Timing Attack if enabled. The highest threat of this issue is confidentiality. This flaw is related to the implementation of the ScramServer class, which may lead to information disclosure due to inconsistency. Exploitation of this issue may allow a remote attacker to gain unauthorized access to protected information.
Recommendations
For versions prior to 1.10.14.Final, update to version 1.10.14.Final or later.
For versions prior to 1.15.5.Final, update to version 1.15.5.Final or later.
For versions prior to 1.16.1.Final, update to version 1.16.1.Final or later.
As a temporary workaround, consider disabling the ScramServer feature until a patch is available.
Fix
Side Channel Attack
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wildfly Elytron