A flaw was found in all supported versions before wildfly-elytron-1.6.8.Final-redhat-00001, where the WildFlySecurityManager checks were bypassed when using custom security managers, resulting in an improper authorization. This flaw leads to information exposure by unauthenticated access to secure resources.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2020-09-16T15:27:36

Updated: 2024-08-04T06:46:30.892Z

Reserved: 2019-11-27T00:00:00

Link: CVE-2020-1748

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2020-09-16T16:15:14.950

Modified: 2022-04-28T18:33:01.063

Link: CVE-2020-1748

cve-icon Redhat

Severity : Moderate

Publid Date: 2020-08-06T00:00:00Z

Links: CVE-2020-1748 - Bugzilla