CVE-2018-10934: XSS
A cross-site scripting (XSS) vulnerability was found in the JBoss Management Console versions before 7.1.6.CR1, 7.1.6.GA. Users with roles that can create objects in the application can exploit this to attack other privileged users.
Other sources
A cross-site scripting (XSS) vulnerability was found in the JBoss Management Console. Users with roles that can create objects in the application can exploit this to attack other privileged users.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/wildfly-coreto a version that resolves this vulnerability.Fixed in 7.1.6. - Upgrade
Upgrade
JBoss Management Consoleto a version that resolves this vulnerability.Fixed in 7.1.6.CR1 - Upgrade
Upgrade
JBoss Management Consoleto a version that resolves this vulnerability.Fixed in 7.1.6.GA
Event History
Frequently Asked Questions
What is the severity of CVE-2018-10934?
CVE-2018-10934 is a cross-site scripting (XSS) vulnerability that allows for potential exploitation by users with specific roles.
How do I fix CVE-2018-10934?
To mitigate CVE-2018-10934, users should update their JBoss Management Console to versions 7.1.6.CR1, 7.1.6.GA or later.
What software is affected by CVE-2018-10934?
CVE-2018-10934 affects JBoss Management Console versions prior to 7.1.6.CR1 and 7.1.6.GA.
Can CVE-2018-10934 be exploited by regular users?
No, only users with roles that can create objects in the application can exploit CVE-2018-10934.
What type of vulnerability is CVE-2018-10934?
CVE-2018-10934 is classified as a cross-site scripting (XSS) vulnerability.