Description
A flaw was found in Wildfly. An incorrect JBOSS_LOCAL_USER challenge location when using the elytron configuration may lead to JBOSS_LOCAL_USER access to all users on the machine. The highest threat from this vulnerability is to confidentiality, integrity, and availability. This flaw affects wildfly-core versions prior to 17.0.
References (2)
Core 2
Core References
Issue Tracking, Third Party Advisory x_refsource_misc
https://bugzilla.redhat.com/show_bug.cgi?id=1991305
Third Party Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20220804-0002/
Scores
CVSS v3
7.8
EPSS
0.0004
EPSS Percentile
11.5%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-552
Status
published
Products (6)
org.wildfly.core/wildfly-core-parent
0 - 17.0Maven
redhat/jboss_enterprise_application_platform
redhat/jboss_enterprise_application_platform
7.4
redhat/jboss_enterprise_application_platform
7.3
redhat/single_sign-on
redhat/wildfly_core
< 17.0
Published
May 24, 2022
Tracked Since
Feb 18, 2026