Wildfly-core: management user rbac permission allows unexpected reading of system-properties to an unauthorized actor
CVE-2023-4061
6.5MEDIUM
Key Information:
What is CVE-2023-4061?
A flaw was found in wildfly-core. A management user could use the resolve-expression in the HAL Interface to read possible sensitive information from the Wildfly system. This issue could allow a malicious user to access the system and obtain possible sensitive information from the system.
Affected Version(s)
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 0:7.4.13-8.GA_redhat_00001.1.el8eap
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 0:1.15.20-1.Final_redhat_00001.1.el8eap
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 0:7.4.13-8.GA_redhat_00001.1.el9eap