Wildfly-core: management user rbac permission allows unexpected reading of system-properties to an unauthorized actor
CVE-2023-4061
6.5MEDIUM
Key Information:
- Vendor
Red Hat
- Status
- Vendor
- CVE Published:
- 8 November 2023
What is CVE-2023-4061?
A flaw was found in wildfly-core. A management user could use the resolve-expression in the HAL Interface to read possible sensitive information from the Wildfly system. This issue could allow a malicious user to access the system and obtain possible sensitive information from the system.