CVE-2021-3644
published 2022-08-26CVE-2021-3644: A flaw was found in wildfly-core in all versions. If a vault expression is in the form of a single attribute that contains multiple expressions, a user who was…
PriorityP412low3.3CVSS 3.1
AVNACHPRHUINSUCLILAN
EPSS
0.76%
51.2th percentile
A flaw was found in wildfly-core in all versions. If a vault expression is in the form of a single attribute that contains multiple expressions, a user who was granted access to the management interface can potentially access a vault expression they should not be able to access and possibly retrieve the item which was stored in the vault. The highest threat from this vulnerability is data confidentiality and integrity.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | descision_manager | — | — |
| redhat | wildfly | — | — |
| redhat | wildfly | — | — |
CVSS provenance
nvdv3.13.3LOWCVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N
vendor_redhat6.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
wildfly-core allows user with access to management interface to access vault expression, retrieve item from vault
ghsa·2022-08-27
CVE-2021-3644 [LOW] wildfly-core allows user with access to management interface to access vault expression, retrieve item from vault
wildfly-core allows user with access to management interface to access vault expression, retrieve item from vault
A flaw was found in wildfly-core in all versions. If a vault expression is in the form of a single attribute that contains multiple expressions, a user who was granted access to the management interface can potentially access a vault expression they should not be able to access and possibly retrieve the item which was stored in the vault. The highest threat from this vulnerability is data confidentiality and integrity.
OSV
wildfly-core allows user with access to management interface to access vault expression, retrieve item from vault
osv·2022-08-27
CVE-2021-3644 [LOW] wildfly-core allows user with access to management interface to access vault expression, retrieve item from vault
wildfly-core allows user with access to management interface to access vault expression, retrieve item from vault
A flaw was found in wildfly-core in all versions. If a vault expression is in the form of a single attribute that contains multiple expressions, a user who was granted access to the management interface can potentially access a vault expression they should not be able to access and possibly retrieve the item which was stored in the vault. The highest threat from this vulnerability is data confidentiality and integrity.
Red Hat
kernel: hamradio: defer ax25 kfree after unregister_netdev
vendor_redhat·2024-03-04·CVSS 6.7
CVE-2021-47084 [MEDIUM] CWE-416 kernel: hamradio: defer ax25 kfree after unregister_netdev
kernel: hamradio: defer ax25 kfree after unregister_netdev
[REJECTED CVE] In the Linux kernel, the following vulnerability has been resolved:
hamradio: defer ax25 kfree after unregister_netdev
The Linux kernel CVE team has assigned CVE-2021-47084 to this issue.
Statement: This CVE has been rejected upstream: https://lore.kernel.org/linux-cve-announce/2024031926-REJECTED-3644@gregkh/
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel (Red Hat Enterprise Linux 8) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 8) - Not affected
Package: kernel (Red Hat Enterprise Linux 9) - Not affected
Package: kernel-rt (Red Hat Enterprise
Red Hat
wildfly-core: Invalid Sensitivity Classification of Vault Expression
vendor_redhat·2021-07-14·CVSS 3.3
CVE-2021-3644 [LOW] CWE-200 wildfly-core: Invalid Sensitivity Classification of Vault Expression
wildfly-core: Invalid Sensitivity Classification of Vault Expression
A flaw was found in wildfly-core in all versions. If a vault expression is in the form of a single attribute that contains multiple expressions, a user who was granted access to the management interface can potentially access a vault expression they should not be able to access and possibly retrieve the item which was stored in the vault. The highest threat from this vulnerability is data confidentiality and integrity.
A flaw was found in wildfly-core in all versions. If a vault expression is in the form of a single attribute that contains multiple expressions, a user who was granted access to the management interface can potentially access a vault expression they should not be able to access and possibly retrieve the i
No detection rules found.
No public exploits indexed.
https://access.redhat.com/security/cve/CVE-2021-3644https://bugzilla.redhat.com/show_bug.cgi?id=1976052https://github.com/wildfly/wildfly-core/commit/06dd9884f6ba50470b1fb5a35198a8784f037714https://github.com/wildfly/wildfly-core/commit/6d8db43cd43b5994b7a14003db978064e086090bhttps://github.com/wildfly/wildfly-core/pull/4668https://issues.redhat.com/browse/WFCORE-5511https://access.redhat.com/security/cve/CVE-2021-3644https://bugzilla.redhat.com/show_bug.cgi?id=1976052https://github.com/wildfly/wildfly-core/commit/06dd9884f6ba50470b1fb5a35198a8784f037714https://github.com/wildfly/wildfly-core/commit/6d8db43cd43b5994b7a14003db978064e086090bhttps://github.com/wildfly/wildfly-core/pull/4668https://issues.redhat.com/browse/WFCORE-5511
2022-08-26
Published