Impact
A flaw in WildFly domain mode allows a local or remote attacker who can provide a crafted relative path through the slave-DC wire protocol to read files outside the intended repository directories. The affected LocalFileRepository methods do not verify that resolved paths remain in the configured root, leading to disclosure of sensitive data such as system passwords and keystores. This is a classic path‑traversal weakness represented by CWE‑22. The core vulnerability surface is limited to the domain controller component but can expose configuration files that are critical to the overall application.
Affected Systems
Red Hat JBoss Enterprise Application Platform versions 7 and 8, the Expansion Pack, and Red Hat Single Sign‑On 7 are impacted. No specific product versions are listed, so all current releases of those products that contain the vulnerable WildFly core should be considered vulnerable.
Risk and Exploitability
The CVSS score of 4.4 indicates a moderate severity, while the EPSS score is not available, suggesting no publicly known exploitation trends. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an attacker to obtain the slave host controller secret or to already have localhost access to the slave host controller. If the secret is compromised, the attacker can supply traversal sequences in the protocol to read arbitrary files, but the attack is naturally limited by the pre‑existing credential requirement. Therefore the risk to organizations that enforce strict host controller security is moderate, but patching is still recommended to eliminate the potential for disclosure.
OpenCVE Enrichment