CVE-2021-3642
published 2021-08-05CVE-2021-3642: A flaw was found in Wildfly Elytron in versions prior to 1.10.14.Final, prior to 1.15.5.Final and prior to 1.16.1.Final where ScramServer may be susceptible to…
PriorityP429medium5.3CVSS 3.1
AVNACHPRLUINSUCHINAN
EPSS
0.85%
55.1th percentile
A flaw was found in Wildfly Elytron in versions prior to 1.10.14.Final, prior to 1.15.5.Final and prior to 1.16.1.Final where ScramServer may be susceptible to Timing Attack if enabled. The highest threat of this vulnerability is confidentiality.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| quarkus | quarkus | <= 2.1.4 | — |
| redhat | codeready_studio | — | — |
| redhat | data_grid | — | — |
| redhat | descision_manager | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_fuse | — | — |
| redhat | process_automation | — | — |
| redhat | wildfly_elytron | < 1.10.14 | 1.10.14 |
| redhat | wildfly_elytron | >= 1.11.0 < 1.15.5 | 1.15.5 |
| redhat | wildfly_elytron | >= 1.16.0 < 1.16.1 | 1.16.1 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:P/I:N/A:N
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Observable Discrepancy in Wildfly Elytron
osv·2022-05-24
CVE-2021-3642 [MEDIUM] Observable Discrepancy in Wildfly Elytron
Observable Discrepancy in Wildfly Elytron
A flaw was found in Wildfly Elytron where ScramServer may be susceptible to Timing Attack if enabled. The highest threat of this vulnerability is confidentiality. This flaw affectes Wildfly Elytron versions prior to 1.10.14.Final, prior to 1.15.5.Final and prior to 1.16.1.Final.
GHSA
Observable Discrepancy in Wildfly Elytron
ghsa·2022-05-24
CVE-2021-3642 [MEDIUM] CWE-203 Observable Discrepancy in Wildfly Elytron
Observable Discrepancy in Wildfly Elytron
A flaw was found in Wildfly Elytron where ScramServer may be susceptible to Timing Attack if enabled. The highest threat of this vulnerability is confidentiality. This flaw affectes Wildfly Elytron versions prior to 1.10.14.Final, prior to 1.15.5.Final and prior to 1.16.1.Final.
Red Hat
wildfly-elytron: possible timing attack in ScramServer
vendor_redhat·2021-06-30·CVSS 5.3
CVE-2021-3642 [MEDIUM] CWE-203 wildfly-elytron: possible timing attack in ScramServer
wildfly-elytron: possible timing attack in ScramServer
A flaw was found in Wildfly Elytron in versions prior to 1.10.14.Final, prior to 1.15.5.Final and prior to 1.16.1.Final where ScramServer may be susceptible to Timing Attack if enabled. The highest threat of this vulnerability is confidentiality.
A flaw was found in Wildfly Elytron where ScramServer may be susceptible to Timing Attack if enabled. The highest threat of this vulnerability is confidentiality.
Package: wildfly-elytron (Red Hat build of Quarkus) - Affected
Package: wildfly-elytron (Red Hat Integration Camel K 1) - Fix deferred
Package: wildfly-elytron (Red Hat Integration Camel Quarkus 1) - Affected
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2021-42581 ramda: prototype poisoning
bugzilla·2022-05-10·CVSS 9.1
CVE-2021-42581 [CRITICAL] CVE-2021-42581 ramda: prototype poisoning
CVE-2021-42581 ramda: prototype poisoning
Prototype poisoning in function mapObjIndexed in Ramda 0.27.0 and earlier allows attackers to compromise integrity or availability of application via supplying a crafted object (that contains an own property "__proto__") as an argument to the function.
https://github.com/ramda/ramda/pull/3192
https://jsfiddle.net/3pomzw5g/2/
Discussion:
Created grafana tracking bugs for this issue:
Affects: fedora-34 [bug 2083781]
Affects: fedora-35 [bug 2083783]
Affects: fedora-all [bug 2083780]
Created mkdocs-material tracking bugs for this issue:
Affects: fedora-34 [bug 2083782]
Affects: fedora-35 [bug 2083784]
---
This issue has been addressed in the following products:
Red Hat Ceph Storage 6.1
Via RHSA-2023:3642 https://access.redhat.com/errata/RHS
Bugzilla
CVE-2021-3642 wildfly-elytron: possible timing attack in ScramServer
bugzilla·2021-07-12·CVSS 5.3
CVE-2021-3642 [MEDIUM] CVE-2021-3642 wildfly-elytron: possible timing attack in ScramServer
CVE-2021-3642 wildfly-elytron: possible timing attack in ScramServer
A flaw was found in Wildfly Elytron where ScramServer may be susceptible to Timing Attack if enabled. The highest threat of this vulnerability is confidentiality.
Reference:
https://issues.redhat.com/browse/ELY-2147
Discussion:
This issue has been addressed in the following products:
Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7
Via RHSA-2021:3656 https://access.redhat.com/errata/RHSA-2021:3656
---
This issue has been addressed in the following products:
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8
Via RHSA-2021:3658 https://access.redhat.com/errata/RHSA-2021:3658
---
This issue has been addressed in the following products:
EAP 7.4.1 release
Via RHSA-2021:3660 https://access.red
2021-08-05
Published