A flaw was found in Wildfly Elytron in versions prior to 1.10.14.Final, prior to 1.15.5.Final and prior to 1.16.1.Final where ScramServer may be susceptible to Timing Attack if enabled. The highest threat of this vulnerability is confidentiality.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Quarkus
Subscribe
|
Quarkus
Subscribe
|
|
Redhat
Subscribe
|
Build Of Quarkus
Subscribe
Camel Quarkus
Subscribe
Codeready Studio
Subscribe
Data Grid
Subscribe
Descision Manager
Subscribe
Integration Camel K
Subscribe
Integration Camel Quarkus
Subscribe
Jboss Data Grid
Subscribe
Jboss Enterprise Application Platform
Subscribe
Jboss Enterprise Application Platform Expansion Pack
Subscribe
Jboss Enterprise Bpms Platform
Subscribe
Jboss Fuse
Subscribe
Jbosseapxp
Subscribe
Openshift Application Runtimes
Subscribe
Process Automation
Subscribe
Red Hat Single Sign On
Subscribe
Wildfly Elytron
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-2493 | A flaw was found in Wildfly Elytron in versions prior to 1.10.14.Final, prior to 1.15.5.Final and prior to 1.16.1.Final where ScramServer may be susceptible to Timing Attack if enabled. The highest threat of this vulnerability is confidentiality. |
Github GHSA |
GHSA-5499-qjvh-6j7w | Observable Discrepancy in Wildfly Elytron |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-03T17:01:07.598Z
Reserved: 2021-07-12T00:00:00
Link: CVE-2021-3642
No data.
Status : Modified
Published: 2021-08-05T21:15:13.183
Modified: 2024-11-21T06:22:03.467
Link: CVE-2021-3642
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA