
We found results for “”
CVE-2023-4061
Good to know:


Date: November 7, 2023
A flaw was found in wildfly-core. A management user could use the resolve-expression in the HAL Interface to read possible sensitive information from the Wildfly system. This issue could allow a malicious user to access the system and obtain possible sensitive information from the system.
Language: Java
Severity Score
Related Resources (11)
Severity Score
Weakness Type (CWE)
Exposure of Sensitive Information to an Unauthorized Actor
CWE-200Insufficient Information
NVD-CWE-noinfoTop Fix

Upgrade Version
Upgrade to version org.amqphub.jca:resource-adapter-thorntail-example:no_fix;org.wildfly:wildfly-controller:no_fix;org.wildfly.core:wildfly-controller:22.0.0.Beta1;org.wildfly.core:wildfly-controller:22.0.0.Beta1;org.wildfly.core:wildfly-controller:22.0.0.Beta1;org.infinispan:infinispan-remote:9.0.0.Alpha1;org.wildfly.core:wildfly-cli:22.0.0.Beta1;org.wildfly.core:wildfly-cli:22.0.0.Beta1;org.wildfly.core:wildfly-cli:22.0.0.Beta1;org.jboss.as:jboss-as-controller:no_fix
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | LOW |
User Interaction (UI): | NONE |
Scope (S): | UNCHANGED |
Confidentiality (C): | NONE |
Integrity (I): | HIGH |
Availability (A): | NONE |