org.wildfly.core:wildfly-controller@16.0.1.Final vulnerabilities

Direct Vulnerabilities

Known vulnerabilities in the org.wildfly.core:wildfly-controller package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • M
Information Exposure

org.wildfly.core:wildfly-controller is a The core runtime that is used by the WildFly application server.

Affected versions of this package are vulnerable to Information Exposure via the resolve-expression in the HAL Interface. An attacker can read possible sensitive information from the system by using this function.

Note:

This is only exploitable if the attacker has management user access.

Mitigation:

Administrators are recommended to use Vault, especially the Elytron subsystem, to store potential critical information such as DNS, IPs, and credentials.

How to fix Information Exposure?

Upgrade org.wildfly.core:wildfly-controller to version 22.0.0.Final or higher.

[0,22.0.0.Final)