CVE-2023-4503: Eap-galleon: custom provisioning creates unsecured http-invoker
An improper initialization vulnerability was found in Galleon. When using Galleon to provision custom EAP or EAP-XP servers, the servers are created unsecured. This issue could allow an attacker to access remote HTTP services available from the server.
Other sources
When using Galleon to provision custom EAP or EAP-XP servers, the servers were created unsecured. An attacker could then use this issue to access remote HTTP services available from the server.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-4503?
CVE-2023-4503 is considered a high severity vulnerability due to its potential to expose unsecured servers to remote attacks.
How do I fix CVE-2023-4503?
To fix CVE-2023-4503, ensure you properly initialize Galleon when provisioning servers, following the latest security patches and guidelines.
What software is affected by CVE-2023-4503?
CVE-2023-4503 affects Red Hat JBoss Enterprise Application Platform and its expansion pack, particularly version 7.4.
What are the potential risks associated with CVE-2023-4503?
The risks associated with CVE-2023-4503 include unauthorized access to remote HTTP services and potential data breaches.
Is Red Hat Enterprise Linux affected by CVE-2023-4503?
Red Hat Enterprise Linux versions 7.0, 8.0, and 9.0 are not affected by CVE-2023-4503.