CVE-2021-3644
Summary
| CVE | CVE-2021-3644 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-08-26 16:15:00 UTC |
| Updated | 2022-08-31 20:02:00 UTC |
| Description | A flaw was found in wildfly-core in all versions. If a vault expression is in the form of a single attribute that contains multiple expressions, a user who was granted access to the management interface can potentially access a vault expression they should not be able to access and possibly retrieve the item which was stored in the vault. The highest threat from this vulnerability is data confidentiality and integrity. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [WFCORE-5511] CVE-2021-3644 wildfly-core: Invalid Sensitivity Classification of Vault Expression - Red Hat Issue Tracker | MISC | issues.redhat.com | |
| Merge pull request #4669 from darranl/WFCORE-5511/16.x · wildfly/wildfly-core@06dd988 · GitHub | MISC | github.com | |
| Merge pull request #4668 from darranl/WFCORE-5511/main · wildfly/wildfly-core@6d8db43 · GitHub | MISC | github.com | |
| [WFCORE-5511] wildfly-core: Invalid Sensitivity Classification of Vault Expression by darranl · Pull Request #4668 · wildfly/wildfly-core · GitHub | MISC | github.com | |
| Red Hat Customer Portal - Access to 24x7 support and knowledge | MISC | access.redhat.com | |
| 1976052 – (CVE-2021-3644) CVE-2021-3644 wildfly-core: Invalid Sensitivity Classification of Vault Expression | MISC | bugzilla.redhat.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 239608 Red Hat Update for Red Hat JBoss Enterprise Application Platform 7.3.9 (RHSA-2021:3468)
- 239609 Red Hat Update for Red Hat JBoss Enterprise Application Platform 7.3.9 (RHSA-2021:3467)
- 239610 Red Hat Update for Red Hat JBoss Enterprise Application Platform 7.3.9 (RHSA-2021:3466)
- 239652 Red Hat Update for Red Hat JBoss Enterprise Application Platform 7.4.1 (RHSA-2021:3658)
- 239653 Red Hat Update for Red Hat JBoss Enterprise Application Platform 7.4.1 (RHSA-2021:3656)