Description
A flaw was found in all supported versions before wildfly-elytron-1.6.8.Final-redhat-00001, where the WildFlySecurityManager checks were bypassed when using custom security managers, resulting in an improper authorization. This flaw leads to information exposure by unauthenticated access to secure resources.
Remediation
References
https://bugzilla.redhat.com/show_bug.cgi?id=1807707
https://security.netapp.com/advisory/ntap-20201001-0005/
Related Vulnerabilities
CVE-2022-34305 Vulnerability in maven package org.apache.tomcat:tomcat
CVE-2019-1003087 Vulnerability in maven package org.jenkins-ci.plugins:sinatra-chef-builder
CVE-2022-25867 Vulnerability in maven package io.socket:socket.io-client
CVE-2018-16487 Vulnerability in npm package lodash
CVE-2023-4853 Vulnerability in maven package io.quarkus:quarkus-undertow