CVE-2023-4061: Wildfly-core: management user rbac permission allows unexpected reading of system-properties to an unauthorized actor
A flaw was found in wildfly-core. A management user could use the resolve-expression in the HAL Interface to read possible sensitive information from the Wildfly system. This issue could allow a malicious user to access the system and obtain possible sensitive information from the system.
Other sources
A flaw was found in Wildfly-core. A management user of a role could use the resolve-expression in the HAL Interface and hence read a possible sensitive information from Wildfly system. Note this requires a Management from roles "Monitor" and similar users which is expected to be a small set of users and already high level of access. A malicious user could possibly use this accessing the system with this management user and obtain possible sensitive information from the system. By default, there's no sensitive information. Wildfly administrators are highly recommended to use Vault and especially the current Elytron subsystem to store potential critical information as DNS, IPs and credentials.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this security flaw?
The vulnerability ID for this security flaw is CVE-2023-4061.
What is the severity of CVE-2023-4061?
The severity of CVE-2023-4061 is medium (6.5).
What software is affected by CVE-2023-4061?
The following software is affected by CVE-2023-4061: wildfly-core (version up to 22.0.0.Final), Redhat Wildfly Core (up to version 15.0.30), Redhat JBoss Enterprise Application Platform (version 7.4), Redhat Jboss Enterprise Application Platform (text-only), Redhat Enterprise Linux 7.0, Redhat Enterprise Linux 8.0, Redhat Enterprise Linux 9.0.
How can a management user use the resolve-expression in the HAL interface?
A management user with rbac permission can use the resolve-expression in the HAL Interface to read possible sensitive information from the Wildfly system.
What is the impact of CVE-2023-4061?
The impact of CVE-2023-4061 is that a malicious user could access the system and obtain possible sensitive information from the system.