CVE-2025-23367: Org.wildfly.core:wildfly-server: wildfly improper rbac permission

Published Jan 14, 2025
·
Updated

Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-qr6x-62gq-4ccp. This link is maintained to preserve external references.

Original Description A flaw was found in the Wildfly Server Role Based Access Control (RBAC) provider. When authorization to control management operations is secured using the Role Based Access Control provider, a user without the required privileges can suspend or resume the server. A user with a Monitor or Auditor role is supposed to have only read access permissions and should not be able to suspend the server. The vulnerability is caused by the Suspend and Resume handlers not performing authorization checks to validate whether the current user has the required permissions to proceed with the action.

Other sources

A flaw was found in the Wildfly Server Role Based Access Control (RBAC) provider. When authorization to control management operations is secured using the Role Based Access Control provider, a user without the required privileges can suspend or resume the server. A user with a Monitor or Auditor role is supposed to have only read access permissions and should not be able to suspend the server. The vulnerability is caused by the Suspend and Resume handlers not performing authorization checks to validate whether the current user has the required permissions to proceed with the action.

Impact Standalone server (Domain mode is not affected) with use access control enabled with RBAC provider can be suspended or resumed by unauthorized users. When a server is suspended, the server will stop receiving user requests. The resume handle does the opposite; it will cause a suspended server to start accepting user requests.

Patches Fixed in WildFly Core 27.0.1.Final

Workarounds No workaround available

References See also: https://issues.redhat.com/browse/WFCORE-7153

Acknowledgements The WildFly project would like to thank Claudia Bartolini (TIM S.p.A), Marco Ventura (TIM S.p.A), and Massimiliano Brolli (TIM S.p.A) for reporting this issue. https://www.gruppotim.it/it/footer/red-team.html

GitHub

When the authorization to control management operations is secured using the Role Based Access Control provider a user without the required privileges can suspend or resume the server.

A user with a Monitor or Auditor role is supposed to have only read access permissions and should not be able to suspend the server.

The vulnerability is caused by the Suspend and Resume handlers not performing authorization checks to validate whether the current user has the required permissions to proceed with the action.

When a server is suspended, the server will stop receiving user requests. The resume handle does the opposite; it will cause a suspended server to start accepting user requests.

Standalone server (Domain mode is not affected). RBAC access control must be enabled with RBAC provider. There is a user with a Monitor or Auditor role.

Red Hat

Affected Software

7 affected componentsFixes available
maven/org.wildfly:wildfly-server<=27.0.0.Final
maven/org.wildfly.core:wildfly-server=28.0.0.Beta1
28.0.0.Beta2
maven/org.wildfly.core:wildfly-server<27.0.1.Final
27.0.1.Final
redhat JBoss Enterprise Application Platform>=7.4<7.4.21
redhat JBoss Enterprise Application Platform>=8.0.0<8.0.7
redhat Wildfly<27.0.1
redhat Wildfly=28.0.0-beta1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade maven/org.wildfly.core:wildfly-server to a version that resolves this vulnerability.

    Fixed in 28.0.0.Beta2
  2. Upgrade

    Upgrade maven/org.wildfly.core:wildfly-server to a version that resolves this vulnerability.

    Fixed in 27.0.1.Final
  3. Upgrade

    Upgrade org.wildfly.core:wildfly-server to a version that resolves this vulnerability.

    Fixed in 27.0.1.Final
  4. Configuration

    Ensure RBAC access control is enabled and configured to use the RBAC provider for management operations so authorization checks apply to Suspend/Resume handlers.

    WildFly RBAC provider (access control) RBAC access control must be enabled with RBAC provider = enabled

Event History

Jan 14, 2025
Data Sourced
via Red Hat·03:30 PM
DescriptionSeverityAffected Software
Jan 30, 2025
CVE Published
via MITRE·02:30 PM
Data Sourced
via MITRE·02:30 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Advisory Published
via GitHub·03:31 PM
Jan 31, 2025
Withdrawn
via GitHub·05:34 PM
Advisory Published
via GitHub·05:34 PM
Data Sourced
via GitHub·05:34 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2025-23367?

The severity of CVE-2025-23367 is classified as moderate.

2

How do I fix CVE-2025-23367?

To fix CVE-2025-23367, upgrade Wildfly Server to version 28.0.0.Beta2 or 27.0.1.Final.

3

What impact does CVE-2025-23367 have on Wildfly Server?

CVE-2025-23367 may lead to unauthorized access due to flaws in the Role Based Access Control (RBAC) provider.

4

Which versions of Wildfly Server are affected by CVE-2025-23367?

CVE-2025-23367 affects Wildfly Server versions prior to 27.0.1.Final and 28.0.0.Beta2.

5

Is CVE-2025-23367 a duplicate vulnerability?

Yes, CVE-2025-23367 has been withdrawn as it is a duplicate of GHSA-qr6x-62gq-4ccp.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203