CVE-2020-10740
published 2020-06-22CVE-2020-10740: A vulnerability was found in Wildfly in versions before 20.0.0.Final, where a remote deserialization attack is possible in the Enterprise Application…
PriorityP346high7.5CVSS 3.1
AVNACHPRLUINSUCHIHAH
EPSS
1.72%
74.9th percentile
A vulnerability was found in Wildfly in versions before 20.0.0.Final, where a remote deserialization attack is possible in the Enterprise Application Beans(EJB) due to lack of validation/filtering capabilities in wildfly.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | wildfly | < 20.0.0 | 20.0.0 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.0MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:P
vendor_redhat6.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Wildfly Unsafe Deserialization Vulnerability
osv·2022-05-24
CVE-2020-10740 [HIGH] Wildfly Unsafe Deserialization Vulnerability
Wildfly Unsafe Deserialization Vulnerability
A vulnerability was found in Wildfly in versions before 20.0.0.Final, where a remote deserialization attack is possible in the Enterprise Application Beans(EJB) due to lack of validation/filtering capabilities in wildfly.
GHSA
Wildfly Unsafe Deserialization Vulnerability
ghsa·2022-05-24
CVE-2020-10740 [HIGH] CWE-502 Wildfly Unsafe Deserialization Vulnerability
Wildfly Unsafe Deserialization Vulnerability
A vulnerability was found in Wildfly in versions before 20.0.0.Final, where a remote deserialization attack is possible in the Enterprise Application Beans(EJB) due to lack of validation/filtering capabilities in wildfly.
Red Hat
wildfly: unsafe deserialization in Wildfly Enterprise Java Beans
vendor_redhat·2020-06-02·CVSS 6.6
CVE-2020-10740 [MEDIUM] CWE-502 wildfly: unsafe deserialization in Wildfly Enterprise Java Beans
wildfly: unsafe deserialization in Wildfly Enterprise Java Beans
A vulnerability was found in Wildfly in versions before 20.0.0.Final, where a remote deserialization attack is possible in the Enterprise Application Beans(EJB) due to lack of validation/filtering capabilities in wildfly.
A flaw was found in Wildfly. A remote deserialization attack is possible in the Enterprise Application Beans (EJB) due to lack of validation/filtering capabilities in wildfly. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availablity.
Mitigation: There is currently no known mitigation for this issue.
Package: wildfly (Red Hat Data Grid 8) - Not affected
Package: wildfly (Red Hat Decision Manager 7) - Not affected
Package: wildfly (Red Hat JBoss Da
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-10740 wildfly: unsafe deserialization in Wildfly Enterprise Java Beans [fedora-all]
bugzilla·2020-06-02·CVSS 6.6
CVE-2020-10740 [MEDIUM] CVE-2020-10740 wildfly: unsafe deserialization in Wildfly Enterprise Java Beans [fedora-all]
CVE-2020-10740 wildfly: unsafe deserialization in Wildfly Enterprise Java Beans [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple sup
Bugzilla
CVE-2020-10740 wildfly: unsafe deserialization in Wildfly Enterprise Java Beans
bugzilla·2020-05-11·CVSS 6.6
CVE-2020-10740 [MEDIUM] CVE-2020-10740 wildfly: unsafe deserialization in Wildfly Enterprise Java Beans
CVE-2020-10740 wildfly: unsafe deserialization in Wildfly Enterprise Java Beans
It was found a flaw in Wildfly where the lack of input validation/filtering capabilities applications running on the application server using it's JNDI or EJB features are left vulnerable to deserialization attacks.
Discussion:
Acknowledgments:
Name: Moritz Bechler (SySS GmbH)
---
Created wildfly tracking bugs for this issue:
Affects: fedora-all [bug 1842967]
---
This issue has been addressed in the following products:
Red Hat JBoss Enterprise Application Platform
Via RHSA-2020:3143 https://access.redhat.com/errata/RHSA-2020:3143
---
This issue has been addressed in the following products:
Red Hat JBoss Enterprise Application Platform
Via RHSA-2020:3144 https://access.redhat.com/errata/RHSA-2020:
2020-06-22
Published