CVE-2020-1748
HIGHWildFly <wildfly-elytron-1.6.8.Final-redhat-00001 - Info Disclosure
Title source: llmDescription
A flaw was found in all supported versions before wildfly-elytron-1.6.8.Final-redhat-00001, where the WildFlySecurityManager checks were bypassed when using custom security managers, resulting in an improper authorization. This flaw leads to information exposure by unauthenticated access to secure resources.
References (2)
Core 2
Core References
Issue Tracking, Vendor Advisory x_refsource_misc
https://bugzilla.redhat.com/show_bug.cgi?id=1807707
Third Party Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20201001-0005/
Scores
CVSS v3
7.5
EPSS
0.0031
EPSS Percentile
54.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Details
Status
published
Products (4)
org.wildfly.security/wildfly-elytron
0 - 1.6.8Maven
redhat/decision_manager
7.0
redhat/process_automation
7.0
redhat/wildfly_elytron
< 1.6.8.final-redhat-00001
Published
Sep 16, 2020
Tracked Since
Feb 18, 2026