wildfly: Wildfly management of EJB Session context returns wrong caller principal with Elytron Security enabled
Published May 10, 2022
5.3
MEDIUMCVSS 3.1
EPSS 0.90%
Description
This is a concurrency issue that can result in the wrong caller principal being returned from the session context of an EJB that is configured with a RunAs principal. In particular, the org.jboss.as.ejb3.component.EJBComponent class has an incomingRunAsIdentity field. This field is used by the org.jboss.as.ejb3.security.RunAsPrincipalInterceptor to keep track of the current identity prior to switching to a new identity created using the RunAs principal. The exploit consist that the EJBComponent#incomingRunAsIdentity field is currently just a SecurityIdentity. This means in a concurrent environment, where multiple users are repeatedly invoking an EJB that is configured with a RunAs principal, it's possible for the wrong the caller principal to be returned from EJBComponent#getCallerPrincipal. Similarly, it's also possible for EJBComponent#isCallerInRole to return the wrong value. Both of these methods rely on incomingRunAsIdentity. Affects all versions of JBoss EAP from 7.1.0 and all versions of WildFly 11+ when Elytron is enabled.
Affected products
- Vendor n/a Product Wildfly Defaultunknown
Affected
- JBoss EAP from 7.1.0 and all versions of WildFly 11+ when Elytron is enabled.
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| n/a | Wildfly | unknown | Affected
|
- ≥ 7.1.0
- 13.0
- ≥ 11.0.0 · < 26.1.1
- 27.0.0
No data.
Red Hat JBoss Enterprise Application Platform 7
wildfly
Fixed · RHSA-2022:4922
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8
eap7-wildfly-0:7.4.5-3.GA_redhat_00001.1.el8eap
Fixed · RHSA-2022:4919
Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7
eap7-wildfly-0:7.4.5-3.GA_redhat_00001.1.el7eap
Fixed · RHSA-2022:4918
Red Hat Single Sign-On 7
wildfly
Fixed · RHSA-2022:6787
Red Hat Single Sign-On 7.5 for RHEL 7
rh-sso7-keycloak-0:15.0.8-1.redhat_00001.1.el7sso
Fixed · RHSA-2022:6782
Red Hat Single Sign-On 7.5 for RHEL 8
rh-sso7-keycloak-0:15.0.8-1.redhat_00001.1.el8sso
Fixed · RHSA-2022:6783
Red Hat Single Sign-On 7.6 for RHEL 7
rh-sso7-keycloak-0:18.0.3-1.redhat_00001.1.el7sso
Fixed · RHSA-2022:7409
Red Hat Single Sign-On 7.6 for RHEL 8
rh-sso7-keycloak-0:18.0.3-1.redhat_00001.1.el8sso
Fixed · RHSA-2022:7410
Red Hat Single Sign-On 7.6 for RHEL 9
rh-sso7-0:1-5.el9sso
Fixed · RHSA-2022:7411
Red Hat Single Sign-On 7.6 for RHEL 9
rh-sso7-javapackages-tools-0:6.0.0-7.el9sso
Fixed · RHSA-2022:7411
Red Hat Single Sign-On 7.6 for RHEL 9
rh-sso7-keycloak-0:18.0.3-1.redhat_00001.1.el9sso
Fixed · RHSA-2022:7411
Red Hat Single Sign-On 7.6.1
wildfly
Fixed · RHSA-2022:7417
Red Hat Data Grid 8
wildfly
Not affected
Red Hat Decision Manager 7
wildfly
Out of support scope
Red Hat Fuse 7
wildfly
Not affected
Red Hat Integration Camel K 1
wildfly
Not affected
Red Hat Integration Camel Quarkus 1
wildfly
Not affected
Red Hat Integration Data Virtualisation Operator
wildfly
Not affected
Red Hat Integration Service Registry
wildfly
Not affected
Red Hat JBoss Data Grid 7
wildfly
Out of support scope
Red Hat JBoss Enterprise Application Platform 6
keycloak-adapter-eap6
Out of support scope
Red Hat JBoss Enterprise Application Platform 6
keycloak-adapter-sso7_2-eap6
Out of support scope
Red Hat JBoss Enterprise Application Platform 6
keycloak-adapter-sso7_3-eap6
Out of support scope
Red Hat JBoss Enterprise Application Platform 6
keycloak-adapter-sso7_4-eap6
Out of support scope
Red Hat JBoss Enterprise Application Platform 6
keycloak-adapter-sso7_5-eap6
Out of support scope
Red Hat JBoss Enterprise Application Platform 6
wildfly
Out of support scope
Red Hat JBoss Enterprise Application Platform Expansion Pack
wildfly
Not affected
Red Hat JBoss Fuse 6
wildfly
Out of support scope
Red Hat JBoss Fuse Service Works 6
wildfly
Out of support scope
Red Hat OpenStack Platform 13 (Queens)
opendaylight
Out of support scope
Red Hat Process Automation 7
wildfly
Out of support scope
Red Hat build of Apicurio Registry 2
wildfly
Not affected
Red Hat build of Debezium 1
wildfly
Not affected
Red Hat build of Quarkus
wildfly
Not affected
streams for Apache Kafka
wildfly
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat JBoss Enterprise Application Platform 7 | wildfly | Fixed | RHSA-2022:4922 |
| Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 | eap7-wildfly-0:7.4.5-3.GA_redhat_00001.1.el8eap | Fixed | RHSA-2022:4919 |
| Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7 | eap7-wildfly-0:7.4.5-3.GA_redhat_00001.1.el7eap | Fixed | RHSA-2022:4918 |
| Red Hat Single Sign-On 7 | wildfly | Fixed | RHSA-2022:6787 |
| Red Hat Single Sign-On 7.5 for RHEL 7 | rh-sso7-keycloak-0:15.0.8-1.redhat_00001.1.el7sso | Fixed | RHSA-2022:6782 |
| Red Hat Single Sign-On 7.5 for RHEL 8 | rh-sso7-keycloak-0:15.0.8-1.redhat_00001.1.el8sso | Fixed | RHSA-2022:6783 |
| Red Hat Single Sign-On 7.6 for RHEL 7 | rh-sso7-keycloak-0:18.0.3-1.redhat_00001.1.el7sso | Fixed | RHSA-2022:7409 |
| Red Hat Single Sign-On 7.6 for RHEL 8 | rh-sso7-keycloak-0:18.0.3-1.redhat_00001.1.el8sso | Fixed | RHSA-2022:7410 |
| Red Hat Single Sign-On 7.6 for RHEL 9 | rh-sso7-0:1-5.el9sso | Fixed | RHSA-2022:7411 |
| Red Hat Single Sign-On 7.6 for RHEL 9 | rh-sso7-javapackages-tools-0:6.0.0-7.el9sso | Fixed | RHSA-2022:7411 |
| Red Hat Single Sign-On 7.6 for RHEL 9 | rh-sso7-keycloak-0:18.0.3-1.redhat_00001.1.el9sso | Fixed | RHSA-2022:7411 |
| Red Hat Single Sign-On 7.6.1 | wildfly | Fixed | RHSA-2022:7417 |
| Red Hat Data Grid 8 | wildfly | Not affected | n/a |
| Red Hat Decision Manager 7 | wildfly | Out of support scope | n/a |
| Red Hat Fuse 7 | wildfly | Not affected | n/a |
| Red Hat Integration Camel K 1 | wildfly | Not affected | n/a |
| Red Hat Integration Camel Quarkus 1 | wildfly | Not affected | n/a |
| Red Hat Integration Data Virtualisation Operator | wildfly | Not affected | n/a |
| Red Hat Integration Service Registry | wildfly | Not affected | n/a |
| Red Hat JBoss Data Grid 7 | wildfly | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | keycloak-adapter-eap6 | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | keycloak-adapter-sso7_2-eap6 | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | keycloak-adapter-sso7_3-eap6 | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | keycloak-adapter-sso7_4-eap6 | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | keycloak-adapter-sso7_5-eap6 | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | wildfly | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform Expansion Pack | wildfly | Not affected | n/a |
| Red Hat JBoss Fuse 6 | wildfly | Out of support scope | n/a |
| Red Hat JBoss Fuse Service Works 6 | wildfly | Out of support scope | n/a |
| Red Hat OpenStack Platform 13 (Queens) | opendaylight | Out of support scope | n/a |
| Red Hat Process Automation 7 | wildfly | Out of support scope | n/a |
| Red Hat build of Apicurio Registry 2 | wildfly | Not affected | n/a |
| Red Hat build of Debezium 1 | wildfly | Not affected | n/a |
| Red Hat build of Quarkus | wildfly | Not affected | n/a |
| streams for Apache Kafka | wildfly | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
JBoss EAP 7.1 until 7.4 is not affected by default as it comes with Legacy Security enabled out-of-the-box. This only affects application scope range and the methods mentioned, no access to server data.
Red Hat mitigation
In order to avoid the possibility of information access, review application source code for '@RunAs' and 'run-as-principal' usage. Also, make sure the application is using or not Elytron Security. It's possible to investigate by checking if the commands from '$JBOSS_HOME/docs/examples/enable-elytron.cli' or similar were executed.
References (6)
- https://access.redhat.com/security/cve/CVE-2022-0866 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2060929 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=2060929#c0 x_refsource_MISCIssue TrackingMitigationVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-15908 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-0866
- https://www.cve.org/CVERecord?id=CVE-2022-0866
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-0866 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2060929 | Issue Tracking | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2060929#c0 | x_refsource_MISCIssue TrackingMitigationVendor Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-15908 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-0866 | ||
| https://www.cve.org/CVERecord?id=CVE-2022-0866 |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub
No data