Description
A flaw was found in all supported versions before wildfly-elytron-1.6.8.Final-redhat-00001, where the WildFlySecurityManager checks were bypassed when using custom security managers, resulting in an improper authorization. This flaw leads to information exposure by unauthenticated access to secure resources.
Remediation
References
https://bugzilla.redhat.com/show_bug.cgi?id=1807707
https://security.netapp.com/advisory/ntap-20201001-0005/
Related Vulnerabilities
CVE-2021-28860 Vulnerability in npm package mixme
CVE-2018-19056 Vulnerability in maven package org.webjars.bower:editor.md
CVE-2022-23496 Vulnerability in maven package nl.basjes.parse.useragent:yauaa-elasticsearch-8
CVE-2020-6467 Vulnerability in maven package org.webjars.npm:electron
CVE-2023-46243 Vulnerability in maven package org.xwiki.platform:xwiki-platform-oldcore