Redhat Wildfly Elytron vulnerabilities

4 known vulnerabilities affecting redhat/wildfly_elytron.

Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH3MEDIUM1

Vulnerabilities

Page 1 of 1
CVE-2022-3143HIGHCVSS 7.4v1.15.152023-01-13
CVE-2022-3143 [HIGH] CWE-203 CVE-2022-3143: wildfly-elytron: possible timing attacks via use of unsafe comparator. A flaw was found in Wildfly-e wildfly-elytron: possible timing attacks via use of unsafe comparator. A flaw was found in Wildfly-elytron. Wildfly-elytron uses java.util.Arrays.equals in several places, which is unsafe and vulnerable to timing attacks. To compare values securely, use java.security.MessageDigest.isEqual instead. This flaw allows an attacker to access secure informatio
nvd
CVE-2021-3642MEDIUMCVSS 5.3fixed in 1.10.14≥ 1.11.0, < 1.15.5+1 more2021-08-05
CVE-2021-3642 [MEDIUM] CWE-203 CVE-2021-3642: A flaw was found in Wildfly Elytron in versions prior to 1.10.14.Final, prior to 1.15.5.Final and pr A flaw was found in Wildfly Elytron in versions prior to 1.10.14.Final, prior to 1.15.5.Final and prior to 1.16.1.Final where ScramServer may be susceptible to Timing Attack if enabled. The highest threat of this vulnerability is confidentiality.
nvd
CVE-2020-10714HIGHCVSS 7.5fixed in 1.11.32020-09-23
CVE-2020-10714 [HIGH] CWE-384 CVE-2020-10714: A flaw was found in WildFly Elytron version 1.11.3.Final and before. When using WildFly Elytron FORM A flaw was found in WildFly Elytron version 1.11.3.Final and before. When using WildFly Elytron FORM authentication with a session ID in the URL, an attacker could perform a session fixation attack. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
nvd
CVE-2020-1748HIGHCVSS 7.5fixed in 1.6.8.final-redhat-000012020-09-16
CVE-2020-1748 [HIGH] CVE-2020-1748: A flaw was found in all supported versions before wildfly-elytron-1.6.8.Final-redhat-00001, where th A flaw was found in all supported versions before wildfly-elytron-1.6.8.Final-redhat-00001, where the WildFlySecurityManager checks were bypassed when using custom security managers, resulting in an improper authorization. This flaw leads to information exposure by unauthenticated access to secure resources.
nvd