PT-2025-4864 · Red Hat · Hal+1
Claudia Bartolini
+2
·
Published
2025-01-14
·
Updated
2026-02-10
·
CVE-2025-23366
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Wildfly component versions prior to HAL 3.7.7.Final
Description
A flaw was found in the HAL Console in the Wildfly component, which does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output used as a web page that is served to other users. The attacker must be authenticated as a user that belongs to management groups “SuperUser”, “Admin”, or “Maintainer”. This issue can lead to a cross-site scripting (XSS) vulnerability in the management console.
Recommendations
For versions prior to HAL 3.7.7.Final, update to HAL 3.7.7.Final to resolve the issue. As a temporary workaround, consider restricting access to the management console for users belonging to the “SuperUser”, “Admin”, or “Maintainer” groups until the update is applied.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hal
Wildfly