A flaw was found in wildfly-core. A management user could use the resolve-expression in the HAL Interface to read possible sensitive information from the Wildfly system. This issue could allow a malicious user to access the system and obtain possible sensitive information from the system.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
EUVD-2023-2843 | A flaw was found in wildfly-core. A management user could use the resolve-expression in the HAL Interface to read possible sensitive information from the Wildfly system. This issue could allow a malicious user to access the system and obtain possible sensitive information from the system. |
![]() |
GHSA-26qx-4m49-6cfr | wildfly-core Exposure of Sensitive Information to an Unauthorized Actor vulnerability |
Fixes
Solution
No solution given by the vendor.
Workaround
Wildfly administrators are recommended to use Vault, especially the Elytron subsystem, to store potential critical information such as DNS, IPs, and credentials.
References
History
Sat, 23 Nov 2024 00:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2025-10-10T00:22:11.034Z
Reserved: 2023-08-01T16:39:57.702Z
Link: CVE-2023-4061

Updated: 2024-08-02T07:17:11.509Z

Status : Modified
Published: 2023-11-08T01:15:08.693
Modified: 2024-11-21T08:34:19.580
Link: CVE-2023-4061


No data.