REDHAT-BUG-2483140: Low severity Red Hat JBoss EAP vulnerability
original reporting: https://docs.google.com/document/d/1Rf4NtLudECimDNy8F9clUblm6Avx8yF/edit
Auth Bypass — Elytron OAuth2 introspection bearer param-injection enables cross-audience token swap (JBoss EAP)
Authentication bypass on any EAP application whose security domain is backed by an Elytron token-realm with <oauth2-introspection>. findings/jboss-eap111.md
Affected Software
Event History
Frequently Asked Questions
Which JBoss EAP deployments should be prioritized for review?
Any EAP application whose security domain is backed by an Elytron token-realm configured with <oauth2-introspection> is in scope for the reported issue.
How can administrators identify potentially affected applications?
Review each application's EAP security domain configuration and identify domains that use an Elytron token-realm with an <oauth2-introspection> configuration.
What is the reported security consequence?
The issue is reported as an authentication bypass that can enable a cross-audience token swap through bearer parameter injection.