CVE-2023-4503
published 2024-02-06CVE-2023-4503: An improper initialization vulnerability was found in Galleon. When using Galleon to provision custom EAP or EAP-XP servers, the servers are created unsecured…
PriorityP344high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.72%
49.8th percentile
An improper initialization vulnerability was found in Galleon. When using Galleon to provision custom EAP or EAP-XP servers, the servers are created unsecured. This issue could allow an attacker to access remote HTTP services available from the server.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | jboss_enterprise_application_platform | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6c6r-r3r9-h62j: An improper initialization vulnerability was found in Galleon
ghsa_unreviewed·2024-02-06
CVE-2023-4503 [MEDIUM] CWE-665 GHSA-6c6r-r3r9-h62j: An improper initialization vulnerability was found in Galleon
An improper initialization vulnerability was found in Galleon. When using Galleon to provision custom EAP or EAP-XP servers, the servers are created unsecured. This issue could allow an attacker to access remote HTTP services available from the server.
Red Hat
eap-galleon: custom provisioning creates unsecured http-invoker
vendor_redhat·2023-12-04·CVSS 6.8
CVE-2023-4503 [MEDIUM] CWE-665 eap-galleon: custom provisioning creates unsecured http-invoker
eap-galleon: custom provisioning creates unsecured http-invoker
An improper initialization vulnerability was found in Galleon. When using Galleon to provision custom EAP or EAP-XP servers, the servers are created unsecured. This issue could allow an attacker to access remote HTTP services available from the server.
An improper initialization vulnerability was found in Galleon. When using Galleon to provision custom EAP or EAP-XP servers, the servers are created unsecured. This issue could allow an attacker to access remote HTTP services available from the server.
Package: eap-galleon (Red Hat JBoss Enterprise Application Platform Expansion Pack) - Affected
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://access.redhat.com/errata/RHSA-2023:7637https://access.redhat.com/errata/RHSA-2023:7638https://access.redhat.com/errata/RHSA-2023:7639https://access.redhat.com/errata/RHSA-2023:7641https://access.redhat.com/security/cve/CVE-2023-4503https://bugzilla.redhat.com/show_bug.cgi?id=2184751https://access.redhat.com/errata/RHSA-2023:7637https://access.redhat.com/errata/RHSA-2023:7638https://access.redhat.com/errata/RHSA-2023:7639https://access.redhat.com/errata/RHSA-2023:7641https://access.redhat.com/security/cve/CVE-2023-4503https://bugzilla.redhat.com/show_bug.cgi?id=2184751
2024-02-06
Published