CVE-2022-1278
published 2022-09-13CVE-2022-1278: A flaw was found in WildFly, where an attacker can see deployment names, endpoints, and any other data the trace payload may contain.
PriorityP338high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.75%
50.8th percentile
A flaw was found in WildFly, where an attacker can see deployment names, endpoints, and any other data the trace payload may contain.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | amq | — | — |
| redhat | jboss_a-mq | — | — |
| redhat | single_sign-on | — | — |
| redhat | wildfly | < 27.0.0 | 27.0.0 |
| redhat | wildfly | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
WildFly vulnerable to Insecure Default Initialization of Resource
osv·2022-09-14
CVE-2022-1278 [HIGH] WildFly vulnerable to Insecure Default Initialization of Resource
WildFly vulnerable to Insecure Default Initialization of Resource
A flaw was found in WildFly, where an attacker can see deployment names, endpoints, and any other data the trace payload may contain.
GHSA
WildFly vulnerable to Insecure Default Initialization of Resource
ghsa·2022-09-14
CVE-2022-1278 [HIGH] CWE-1188 WildFly vulnerable to Insecure Default Initialization of Resource
WildFly vulnerable to Insecure Default Initialization of Resource
A flaw was found in WildFly, where an attacker can see deployment names, endpoints, and any other data the trace payload may contain.
Red Hat
WildFly: possible information disclosure
vendor_redhat·2022-04-08·CVSS 7.5
CVE-2022-1278 [HIGH] CWE-1188 WildFly: possible information disclosure
WildFly: possible information disclosure
A flaw was found in WildFly, where an attacker can see deployment names, endpoints, and any other data the trace payload may contain.
A flaw was found in WildFly. This flaw allows an attacker to see deployment names, endpoints, and any other data the trace payload may contain.
Package: WildFly (A-MQ Clients 2) - Not affected
Package: WildFly (Red Hat A-MQ Online) - Not affected
Package: WildFly (Red Hat build of Apicurio Registry 2) - Not affected
Package: WildFly (Red Hat build of Debezium 1) - Not affected
Package: WildFly (Red Hat build of Quarkus) - Not affected
Package: WildFly (Red Hat Data Grid 8) - Fix deferred
Package: WildFly (Red Hat Decision Manager 7) - Fix deferred
Package: WildFly (Red Hat Fuse 7) - Fix deferred
Package: Wi
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-09-13
Published