CVE-2022-1278

CWE-11885 documents5 sources
Severity
7.5HIGH
EPSS
0.9%
top 24.60%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 13
Latest updateSep 14

Description

A flaw was found in WildFly, where an attacker can see deployment names, endpoints, and any other data the trace payload may contain.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages6 packages

NVDredhat/wildfly< 27.0.0
Mavenorg.wildfly.bom:wildfly< 27.0.0.Beta1
CVEListV5wildflyno fixed versions known
NVDredhat/amq2.0

🔴Vulnerability Details

3
OSV
WildFly vulnerable to Insecure Default Initialization of Resource2022-09-14
GHSA
WildFly vulnerable to Insecure Default Initialization of Resource2022-09-14
CVEList
CVE-2022-1278: A flaw was found in WildFly, where an attacker can see deployment names, endpoints, and any other data the trace payload may contain2022-09-13

📋Vendor Advisories

1
Red Hat
WildFly: possible information disclosure2022-04-08