CVE-2025-23366: Org.jboss.hal:hal-console: wildfly hal console cross-site scripting
Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-jhvj-f397-8w6q. This link is maintained to preserve external references.
Original Description A flaw was found in the HAL Console in the Wildfly component, which does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output used as a web page that is served to other users. The attacker must be authenticated as a user that belongs to management groups “SuperUser”, “Admin”, or “Maintainer”.
Other sources
A flaw was found in the HAL Console in the Wildfly component, which does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output used as a web page that is served to other users. The attacker must be authenticated as a user that belongs to management groups “SuperUser”, “Admin”, or “Maintainer”.
Impact Cross-site scripting (XSS) vulnerability in the management console.
Patches Fixed in HAL 3.7.7.Final
Workarounds No workaround available
References - https://access.redhat.com/security/cve/CVE-2025-23366 - https://bugzilla.redhat.com/showbug.cgi?id=2337619
— GitHub
Wildfly does not neutralize or incorrectly neutralizes user- controllable input before it is placed in output that is used as a web page that is served to other users.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/org.jboss.hal:hal-consoleto a version that resolves this vulnerability.Fixed in 3.7.7.Final - Upgrade
Upgrade
Org.jboss.hal:hal-console (Wildfly component)to a version that resolves this vulnerability.Fixed in 3.7.7.Final
Event History
Frequently Asked Questions
What is the severity of CVE-2025-23366?
CVE-2025-23366 has been marked as a duplicate advisory and does not have a severity rating associated with it.
How do I fix CVE-2025-23366?
To mitigate the issues associated with CVE-2025-23366, update the Wildfly component to a version that is not affected, such as any version above 3.7.7.Final.
Which versions of the Wildfly component are affected by CVE-2025-23366?
CVE-2025-23366 affects versions of the Wildfly component up to and including 3.7.7.Final.
Is CVE-2025-23366 still relevant?
CVE-2025-23366 is considered a duplicate advisory and is no longer maintained as an independent concern.
Where can I find more information on CVE-2025-23366?
Additional technical details regarding CVE-2025-23366 may be found in the associated advisories and reports from security sources.