PT-2025-4864 · Red Hat · Hal+1

Claudia Bartolini

+2

·

Published

2025-01-14

·

Updated

2026-02-10

·

CVE-2025-23366

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Wildfly component versions prior to HAL 3.7.7.Final
Description A flaw was found in the HAL Console in the Wildfly component, which does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output used as a web page that is served to other users. The attacker must be authenticated as a user that belongs to management groups “SuperUser”, “Admin”, or “Maintainer”. This issue can lead to a cross-site scripting (XSS) vulnerability in the management console.
Recommendations For versions prior to HAL 3.7.7.Final, update to HAL 3.7.7.Final to resolve the issue. As a temporary workaround, consider restricting access to the management console for users belonging to the “SuperUser”, “Admin”, or “Maintainer” groups until the update is applied.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-23366
GHSA-5WJW-H8X5-V65M
GHSA-JHVJ-F397-8W6Q
RHSA-2025:10924
RHSA-2025:10925
RHSA-2025:10926

Affected Products

Hal
Wildfly