CVE-2024-10234
Wildfly: wildfly vulnerable to cross-site scripting (xss)
A vulnerability was found in Wildfly, where a user may perform Cross-site scripting in the Wildfly deployment system. This flaw allows an attacker or insider to execute a deployment with a malicious payload, which could trigger undesired behavior against the server.
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N
Produtos afetados
wildflyRed Hat · Red Hat Build of KeycloakRed Hat · Red Hat Fuse 7Red Hat · Red Hat JBoss Data Grid 7Red Hat · Red Hat JBoss Enterprise Application Platform 7.4.23Red Hat · Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8Red Hat · Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9Red Hat · Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7Red Hat · Red Hat JBoss Enterprise Application Platform 8Red Hat · Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8Red Hat · Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9Red Hat · Red Hat JBoss Enterprise Application Platform Expansion PackRed Hat · Red Hat Single Sign-On 7Red Hat · Red Hat Single Sign-On 7.6 for RHEL 7Red Hat · Red Hat Single Sign-On 7.6 for RHEL 8Red Hat · Red Hat Single Sign-On 7.6 for RHEL 9Red Hat · RHEL-8 based Middleware ContainersQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
https://access.redhat.com/errata/RHSA-2025:10924https://access.redhat.com/errata/RHSA-2025:10925https://access.redhat.com/errata/RHSA-2025:10926https://access.redhat.com/errata/RHSA-2025:10931https://access.redhat.com/errata/RHSA-2025:11636https://access.redhat.com/errata/RHSA-2025:11638https://access.redhat.com/errata/RHSA-2025:11639https://access.redhat.com/errata/RHSA-2025:11640https://access.redhat.com/errata/RHSA-2025:11645https://access.redhat.com/errata/RHSA-2025:2025https://access.redhat.com/errata/RHSA-2025:2026https://access.redhat.com/errata/RHSA-2025:2029