CVE-2022-1278: High severity wildfly vulnerability
A flaw was found in WildFly, where an attacker can see deployment names, endpoints, and any other data the trace payload may contain.
Other sources
A flaw was found in WildFly. This flaw allows an attacker to see deployment names, endpoints, and any other data the trace payload may contain.
Attackers can see deployment names, endpoints, and any other data the trace payload may contain.
Reference:
https://issues.redhat.com/browse/WFLY-16238
— Red Hat
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2022-1278?
CVE-2022-1278 is a vulnerability found in WildFly that allows an attacker to view deployment names, endpoints, and any other data the trace payload may contain.
What is the severity of CVE-2022-1278?
CVE-2022-1278 has a severity level of high.
How does CVE-2022-1278 impact WildFly?
CVE-2022-1278 allows an attacker to access sensitive information, such as deployment names and endpoints, in WildFly.
Are there any known fixes for CVE-2022-1278?
At the moment, there are no known fixes for CVE-2022-1278. It is recommended to apply any patches or updates provided by the vendor once available.
What is the Common Weakness Enumeration (CWE) ID associated with CVE-2022-1278?
CVE-2022-1278 is associated with CWE-1188, which is the CWE ID for 'Missing Authorization.'