PT-2021-3878 · Red Hat · Wildfly Elytron

Guilherme De Almeida Suckevicz

·

Published

2021-06-30

·

Updated

2022-05-24

·

CVE-2021-3642

CVSS v3.1

5.3

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Wildfly Elytron versions prior to 1.10.14.Final Wildfly Elytron versions prior to 1.15.5.Final Wildfly Elytron versions prior to 1.16.1.Final
Description A flaw was found in Wildfly Elytron where ScramServer may be susceptible to Timing Attack if enabled. The highest threat of this issue is confidentiality. This flaw is related to the implementation of the ScramServer class, which may lead to information disclosure due to inconsistency. Exploitation of this issue may allow a remote attacker to gain unauthorized access to protected information.
Recommendations For versions prior to 1.10.14.Final, update to version 1.10.14.Final or later. For versions prior to 1.15.5.Final, update to version 1.15.5.Final or later. For versions prior to 1.16.1.Final, update to version 1.16.1.Final or later. As a temporary workaround, consider disabling the ScramServer feature until a patch is available.

Fix

Side Channel Attack

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-04259
CVE-2021-3642
GHSA-5499-QJVH-6J7W
RHSA-2021:3656
RHSA-2021:3658
RHSA-2021:5149
RHSA-2021:5150
RHSA-2021:5151

Affected Products

Wildfly Elytron