A flaw was found in Wildfly where insufficient RBAC restrictions may lead to expose metrics data. The highest threat from this vulnerability is to the confidentiality.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=1942693 | vendor advisory issue tracking |
https://issues.redhat.com/browse/WFLY-11933 | vendor advisory |
https://github.com/wildfly/wildfly/pull/14136 | third party advisory patch |
https://github.com/advisories/GHSA-c4r5-xvgw-2942 | third party advisory |
https://access.redhat.com/security/cve/CVE-2021-3503 | vendor advisory |