CVE-2024-10234
published 2024-10-22CVE-2024-10234: A vulnerability was found in Wildfly, where a user may perform Cross-site scripting in the Wildfly deployment system. This flaw allows an attacker or insider…
PriorityP336high7.3CVSS 3.1
AVNACLPRLUIRSUCHIHAN
ITW
Exploited in the wild
EPSS
0.65%
47.1th percentile
A vulnerability was found in Wildfly, where a user may perform Cross-site scripting in the Wildfly deployment system. This flaw allows an attacker or insider to execute a deployment with a malicious payload, which could trigger undesired behavior against the server.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | jboss_enterprise_application_platform | — | — |
CVSS provenance
nvdv3.17.3HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
vendor_redhat6.1MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-w22f-vwwp-37pr: A vulnerability was found in Wildfly, where a user may perform Cross-site scripting in the Wildfly deployment system
ghsa_unreviewed·2024-10-22
CVE-2024-10234 [MEDIUM] CWE-79 GHSA-w22f-vwwp-37pr: A vulnerability was found in Wildfly, where a user may perform Cross-site scripting in the Wildfly deployment system
A vulnerability was found in Wildfly, where a user may perform Cross-site scripting in the Wildfly deployment system. This flaw allows an attacker or insider to execute a deployment with a malicious payload, which could trigger undesired behavior against the server.
Red Hat
wildfly: Wildfly vulnerable to Cross-Site Scripting (XSS)
vendor_redhat·2024-10-22·CVSS 6.1
CVE-2024-10234 [MEDIUM] CWE-79 wildfly: Wildfly vulnerable to Cross-Site Scripting (XSS)
wildfly: Wildfly vulnerable to Cross-Site Scripting (XSS)
A vulnerability was found in Wildfly, where a user may perform Cross-site scripting in the Wildfly deployment system. This flaw allows an attacker or insider to execute a deployment with a malicious payload, which could trigger undesired behavior against the server.
A vulnerability was found in Wildfly, where a user may perform Cross-site scripting in the Wildfly deployment system. This flaw allows an attacker or insider to execute a deployment with a malicious payload, which could trigger undesired behavior against the server.
Package: org.wildfly.core/wildfly-core-management-subsystem (Red Hat Build of Keycloak) - Will not fix
Package: org.wildfly.core/wildfly-core-management-subsystem (Red Hat Fuse 7) - Out of support scope
No detection rules found.
No public exploits indexed.
https://access.redhat.com/errata/RHSA-2025:10924https://access.redhat.com/errata/RHSA-2025:10925https://access.redhat.com/errata/RHSA-2025:10926https://access.redhat.com/errata/RHSA-2025:10931https://access.redhat.com/errata/RHSA-2025:11636https://access.redhat.com/errata/RHSA-2025:11638https://access.redhat.com/errata/RHSA-2025:11639https://access.redhat.com/errata/RHSA-2025:11640https://access.redhat.com/errata/RHSA-2025:11645https://access.redhat.com/errata/RHSA-2025:2025https://access.redhat.com/errata/RHSA-2025:2026https://access.redhat.com/errata/RHSA-2025:2029https://access.redhat.com/security/cve/CVE-2024-10234https://bugzilla.redhat.com/show_bug.cgi?id=2320848
2024-10-22
Published
Exploited in the wild