PT-2023-27539 · Unknown · Wildfly-Core

Patrick Del Bello

·

Published

2023-11-08

·

Updated

2023-11-16

·

CVE-2023-4061

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Wildfly-core (affected versions not specified)
Description A flaw in wildfly-core allows a management user to use the resolve-expression in the HAL Interface to read possible sensitive information from the Wildfly system. This could enable a malicious user to access the system and obtain sensitive information.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2023-4061
GHSA-26QX-4M49-6CFR
RHSA-2023:5484
RHSA-2023:5485
RHSA-2023:5486

Affected Products

Wildfly-Core