Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-4061


A flaw was found in wildfly-core. A management user could use the resolve-expression in the HAL Interface to read possible sensitive information from the Wildfly system. This issue could allow a malicious user to access the system and obtain possible sensitive information from the system.


Published

2023-11-08T01:15:08.693

Last Modified

2024-11-21T08:34:19.580

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.5 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-200
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application redhat jboss_enterprise_application_platform - Yes
Application redhat wildfly_core < 15.0.30 Yes
Application redhat jboss_enterprise_application_platform 7.4 Yes
Operating System redhat enterprise_linux 7.0 No
Operating System redhat enterprise_linux 8.0 No
Operating System redhat enterprise_linux 9.0 No

References