A flaw was found in wildfly-core. A management user could use the resolve-expression in the HAL Interface to read possible sensitive information from the Wildfly system. This issue could allow a malicious user to access the system and obtain possible sensitive information from the system.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-2843 | A flaw was found in wildfly-core. A management user could use the resolve-expression in the HAL Interface to read possible sensitive information from the Wildfly system. This issue could allow a malicious user to access the system and obtain possible sensitive information from the system. |
Github GHSA |
GHSA-26qx-4m49-6cfr | wildfly-core Exposure of Sensitive Information to an Unauthorized Actor vulnerability |
Fixes
Solution
No solution given by the vendor.
Workaround
Wildfly administrators are recommended to use Vault, especially the Elytron subsystem, to store potential critical information such as DNS, IPs, and credentials.
References
History
Sat, 23 Nov 2024 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2025-11-07T10:37:04.606Z
Reserved: 2023-08-01T16:39:57.702Z
Link: CVE-2023-4061
Updated: 2024-08-02T07:17:11.509Z
Status : Modified
Published: 2023-11-08T01:15:08.693
Modified: 2024-11-21T08:34:19.580
Link: CVE-2023-4061
OpenCVE Enrichment
No data.
EUVD
Github GHSA