CVE-2020-1748

HIGH

WildFly <wildfly-elytron-1.6.8.Final-redhat-00001 - Info Disclosure

Title source: llm
STIX 2.1

Description

A flaw was found in all supported versions before wildfly-elytron-1.6.8.Final-redhat-00001, where the WildFlySecurityManager checks were bypassed when using custom security managers, resulting in an improper authorization. This flaw leads to information exposure by unauthenticated access to secure resources.

References (2)

Core 2
Core References
Issue Tracking, Vendor Advisory x_refsource_misc
https://bugzilla.redhat.com/show_bug.cgi?id=1807707
Third Party Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20201001-0005/

Scores

CVSS v3 7.5
EPSS 0.0031
EPSS Percentile 54.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

Status published
Products (4)
org.wildfly.security/wildfly-elytron 0 - 1.6.8Maven
redhat/decision_manager 7.0
redhat/process_automation 7.0
redhat/wildfly_elytron < 1.6.8.final-redhat-00001
Published Sep 16, 2020
Tracked Since Feb 18, 2026