CVE-2020-1748
published 2020-09-16CVE-2020-1748: A flaw was found in all supported versions before wildfly-elytron-1.6.8.Final-redhat-00001, where the WildFlySecurityManager checks were bypassed when using…
PriorityP344high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
1.44%
70.2th percentile
A flaw was found in all supported versions before wildfly-elytron-1.6.8.Final-redhat-00001, where the WildFlySecurityManager checks were bypassed when using custom security managers, resulting in an improper authorization. This flaw leads to information exposure by unauthenticated access to secure resources.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | decision_manager | — | — |
| redhat | process_automation | — | — |
| redhat | wildfly_elytron | < 1.6.8.final-redhat-00001 | 1.6.8.final-redhat-00001 |
| redhat | wildfly_elytron | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Wildfly: Improper authorization issue in WildFlySecurityManager when using alternative protection domain
vendor_redhat·2020-08-06·CVSS 7.5
CVE-2020-1748 [HIGH] CWE-285 Wildfly: Improper authorization issue in WildFlySecurityManager when using alternative protection domain
Wildfly: Improper authorization issue in WildFlySecurityManager when using alternative protection domain
A flaw was found in all supported versions before wildfly-elytron-1.6.8.Final-redhat-00001, where the WildFlySecurityManager checks were bypassed when using custom security managers, resulting in an improper authorization. This flaw leads to information exposure by unauthenticated access to secure resources.
A flaw was found in Wildfly, where the WildFlySecurityManager checks were bypassed when using custom security managers, resulting in an improper authorization. This flaw leads to information exposure by unauthenticated access to secure resources.
Package: wildfly (Red Hat Fuse 7) - Will not fix
Package: jbossas (Red Hat JBoss Data Virtualization 6) - Out of support scope
Packag
OSV
Incorrect Authorization in WildFly Elytron
osv·2022-02-15
CVE-2020-1748 [HIGH] Incorrect Authorization in WildFly Elytron
Incorrect Authorization in WildFly Elytron
A flaw was found in all supported versions before wildfly-elytron-1.6.8.Final-redhat-00001, where the WildFlySecurityManager checks were bypassed when using custom security managers, resulting in an improper authorization. This flaw leads to information exposure by unauthenticated access to secure resources.
GHSA
Incorrect Authorization in WildFly Elytron
ghsa·2022-02-15
CVE-2020-1748 [HIGH] CWE-863 Incorrect Authorization in WildFly Elytron
Incorrect Authorization in WildFly Elytron
A flaw was found in all supported versions before wildfly-elytron-1.6.8.Final-redhat-00001, where the WildFlySecurityManager checks were bypassed when using custom security managers, resulting in an improper authorization. This flaw leads to information exposure by unauthenticated access to secure resources.
No detection rules found.
Bugzilla
CVE-2020-25667 ImageMagick: heap-based buffer overflow in TIFFGetProfiles in coders/tiff.c
bugzilla·2020-10-26·CVSS 5.5
CVE-2020-25667 [MEDIUM] CVE-2020-25667 ImageMagick: heap-based buffer overflow in TIFFGetProfiles in coders/tiff.c
CVE-2020-25667 ImageMagick: heap-based buffer overflow in TIFFGetProfiles in coders/tiff.c
ImageMagick 7.0.8-68 there is a heap-buffer-overflow at coders/tiff.c in TIFFGetProfiles.
Reference:
https://github.com/ImageMagick/ImageMagick/issues/1748
Upstream patch:
https://github.com/ImageMagick/ImageMagick/commit/986b5dff173413fa712db27eb677cdef15f0bab6
Discussion:
Flaw summary:
TIFFGetProfiles() in /coders/tiff.c calls strstr() which causes a large out-of-bounds read when it searches for `"dc:format=\"image/dng\"` within `profile` due to improper string handling, when a crafted input file is provided to ImageMagick. The patch uses a StringInfo type instead of a raw C string to remedy this. This could cause an impact to availability of the application.
---
Acknowledgments:
Name: Suh
Bugzilla
CVE-2020-1748 Wildfly: Improper authorization issue in WildFlySecurityManager when using alternative protection domain
bugzilla·2020-02-27·CVSS 7.5
CVE-2020-1748 [HIGH] CVE-2020-1748 Wildfly: Improper authorization issue in WildFlySecurityManager when using alternative protection domain
CVE-2020-1748 Wildfly: Improper authorization issue in WildFlySecurityManager when using alternative protection domain
A flaw was found in Wildfly. At certain scenarios WildFlySecurityManager checks can by bypassed when using custom security managers.
References:
https://issues.redhat.com/browse/EAPSUP-67
Discussion:
This vulnerability is out of security support scope for the following products:
* Red Hat Enterprise Application Platform 6
* Red Hat Enterprise Application Platform 5
* Red Hat JBoss Operations Network 3
* Red Hat JBoss Data Virtualization & Services 6
* Red Hat JBoss Fuse 6
* Red Hat JBoss SOA Platform 5
Please refer to https://access.redhat.com/support/policy/updates/jboss_notes for more details.
---
This issue has been addressed in the following products:
Red Hat
2020-09-16
Published