REDHAT-BUG-1772008: Medium severity OpenSSL OpenSSL vulnerability
It was found that the OpenSSL security provider does not honor TLS version in 'enabled-protocols' value of Wildfly's legacy security configuration. An attacker could target traffic sent over a TLS connection with a weaker version of TLS and potentially break the encryption of the data stream.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1772008?
The severity of REDHAT-BUG-1772008 is considered critical due to potential data exposure vulnerabilities using weaker TLS versions.
How do I fix REDHAT-BUG-1772008?
To fix REDHAT-BUG-1772008, update your OpenSSL and WildFly components to the latest versions where this issue is addressed.
What systems are affected by REDHAT-BUG-1772008?
REDHAT-BUG-1772008 affects systems running specific versions of OpenSSL and WildFly that improperly handle TLS protocols.
Can REDHAT-BUG-1772008 be exploited remotely?
Yes, an attacker may exploit REDHAT-BUG-1772008 remotely to downgrade TLS connections and potentially access sensitive data.
What configurations are impacted by REDHAT-BUG-1772008?
REDHAT-BUG-1772008 impacts legacy security configurations in WildFly that do not respect the 'enabled-protocols' setting for TLS.