Description
A flaw was found in wildfly-core before 7.2.5.GA. The Management users with Monitor, Auditor and Deployer Roles should not be allowed to modify the runtime state of the server
Remediation
References
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14838
https://access.redhat.com/errata/RHSA-2019:3083
https://access.redhat.com/errata/RHSA-2019:3082
https://access.redhat.com/errata/RHSA-2019:4018
https://access.redhat.com/errata/RHSA-2019:4021
https://access.redhat.com/errata/RHSA-2019:4020
https://access.redhat.com/errata/RHSA-2019:4019
https://access.redhat.com/errata/RHSA-2019:4041
https://access.redhat.com/errata/RHSA-2019:4040
https://access.redhat.com/errata/RHSA-2019:4042
https://access.redhat.com/errata/RHSA-2019:4045
https://access.redhat.com/errata/RHSA-2020:0728
Related Vulnerabilities
CVE-2022-3143 Vulnerability in maven package org.wildfly.security:wildfly-elytron-realm-ldap
CVE-2021-44868 Vulnerability in maven package net.mingsoft:ms-mcms
CVE-2020-1938 Vulnerability in maven package org.apache.tomcat:tomcat-coyote
CVE-2020-2204 Vulnerability in maven package org.jenkins-ci.plugins:fortify-on-demand-uploader
CVE-2022-41915 Vulnerability in maven package io.netty:netty-codec