wildfly: Missing authentication in edfault installation without a security realm reference
Published May 9, 2018
9.8
CRITICALCVSS 3.1
EPSS 1.76%
Description
An issue was discovered in WildFly 10.1.2.Final. In the case of a default installation without a security realm reference, an attacker can successfully access the server without authentication. NOTE: the Security Realms documentation in the product's Admin Guide indicates that "without a security realm reference" implies "effectively unsecured." The vendor explicitly supports these unsecured configurations because they have valid use cases during development
Affected products
No data.
No data.
Red Hat JBoss Data Grid 7
wildfly
Not affected
Red Hat JBoss Enterprise Application Platform 7
wildfly
Not affected
Red Hat Single Sign-On 7
wildfly
Not affected
Red Hat Virtualization 4
eap7-wildfly
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat JBoss Data Grid 7 | wildfly | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 7 | wildfly | Not affected | n/a |
| Red Hat Single Sign-On 7 | wildfly | Not affected | n/a |
| Red Hat Virtualization 4 | eap7-wildfly | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Product Security does not consider this issue to be a vulnerability. The default installation are by default secured and set to have an authentication mechanism in place. It is possible to explicitly remove the realm from the configuration files when needed. For example, in case there's need to run in single user mode for development use, ability to switch off security is desirable so the admin console can be accessed without the need for user accounts. There is adequate mechanism in place to secure the WildFly environment.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
AV:N/AC:L/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v5
Table of values (13 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 1.76% (0.01756) | 77.12th | v5 (v2026.06.15) |
| Jun 15, 2026 | 1.78% (0.01783) | 75.34th | v5 (v2026.06.15) |
| Jul 20, 2024 | 0.66% (0.00659) | 79.83th | v3 (v2023.03.01) |
| Feb 8, 2024 | 0.66% (0.00659) | 78.92th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.66% (0.00659) | 76.42th | v3 (v2023.03.01) |
| Mar 6, 2023 | 0.89% (0.00885) | 27.89th | v2 (v2022.01.01) |
| Sep 10, 2022 | 0.89% (0.00885) | 26.24th | v2 (v2022.01.01) |
| Apr 1, 2022 | 0.89% (0.00885) | 24.24th | v2 (v2022.01.01) |
| Feb 4, 2022 | 0.89% (0.00885) | 10.50th | v2 (v2022.01.01) |
| Feb 3, 2022 | 0.42% (0.00416) | 10.04th | v1 |
| Jan 6, 2022 | 0.42% (0.00416) | 9.79th | v1 |
| Sep 1, 2021 | 0.42% (0.00416) | 25.53th | v1 |
| Apr 14, 2021 | 0.42% (0.00416) | 0.00th | v1 |
References (5)
- https://access.redhat.com/security/cve/CVE-2018-10683 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1636014 Issue Tracking
- https://github.com/kmkz/exploit/blob/master/CVE-2018-10682-CVE-2018-10683.txt x_refsource_MISCExploitThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2018-10683
- https://www.cve.org/CVERecord?id=CVE-2018-10683
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2018-10683 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1636014 | Issue Tracking | |
| https://github.com/kmkz/exploit/blob/master/CVE-2018-10682-CVE-2018-10683.txt | x_refsource_MISCExploitThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2018-10683 | ||
| https://www.cve.org/CVERecord?id=CVE-2018-10683 |
Change history (0)
No recorded changes yet.