Org.wildfly.core:wildfly-server: wildfly improper rbac permission
Published Jan 30, 2025
6.5
MEDIUMCVSS 3.1
EPSS 0.77%
Description
A flaw was found in the Wildfly Server Role Based Access Control (RBAC) provider. When authorization to control management operations is secured using the Role Based Access Control provider, a user without the required privileges can suspend or resume the server. A user with a Monitor or Auditor role is supposed to have only read access permissions and should not be able to suspend the server. The vulnerability is caused by the Suspend and Resume handlers not performing authorization checks to validate whether the current user has the required permissions to proceed with the action.
Affected products
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||
|---|---|---|---|---|---|---|
| Red Hat | Red Hat Data Grid 8 | affected |
| |||
| Red Hat | Red Hat JBoss Enterprise Application Platform 7 | affected |
|
- ≥ 7.4 · < 7.4.21
- ≥ 8.0.0 · < 8.0.7
- < 27.0.1
- 28.0.0
No data.
Red Hat JBoss Enterprise Application Platform
org.wildfly.core/wildfly-server:15.0.45.Final-redhat-00001
Fixed · RHSA-2025:3467
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8
eap7-netty-0:4.1.119-1.Final_redhat_00004.1.el8eap
Fixed · RHSA-2025:3465
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8
eap7-netty-transport-native-epoll-0:4.1.119-1.Final_redhat_00004.1.el8eap
Fixed · RHSA-2025:3465
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8
eap7-wildfly-0:7.4.21-3.GA_29548_redhat_00001.1.el8eap
Fixed · RHSA-2025:3465
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9
eap7-netty-0:4.1.119-1.Final_redhat_00004.1.el9eap
Fixed · RHSA-2025:3465
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9
eap7-netty-transport-native-epoll-0:4.1.119-1.Final_redhat_00004.1.el9eap
Fixed · RHSA-2025:3465
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9
eap7-wildfly-0:7.4.21-3.GA_29548_redhat_00001.1.el9eap
Fixed · RHSA-2025:3465
Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7
eap7-netty-0:4.1.119-1.Final_redhat_00004.1.el7eap
Fixed · RHSA-2025:3465
Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7
eap7-netty-transport-native-epoll-0:4.1.119-1.Final_redhat_00004.1.el7eap
Fixed · RHSA-2025:3465
Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7
eap7-wildfly-0:7.4.21-3.GA_29548_redhat_00001.1.el7eap
Fixed · RHSA-2025:3465
Red Hat JBoss Enterprise Application Platform 7.4.22
org.wildfly.core/wildfly-server:15.0.42.Final-redhat-00001
Fixed · RHSA-2025:4552
Red Hat JBoss Enterprise Application Platform 8
wildfly-server
Fixed · RHSA-2025:3992
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
eap8-apache-commons-io-0:2.16.1-1.redhat_00001.1.el8eap
Fixed · RHSA-2025:3989
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
eap8-bouncycastle-0:1.80.0-1.redhat_00001.1.el8eap
Fixed · RHSA-2025:3989
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
eap8-eap-product-conf-parent-0:800.7.0-2.GA_redhat_00002.1.el8eap
Fixed · RHSA-2025:3989
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
eap8-hibernate-0:6.2.35-1.Final_redhat_00001.1.el8eap
Fixed · RHSA-2025:3989
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
eap8-ironjacamar-0:3.0.13-1.Final_redhat_00001.1.el8eap
Fixed · RHSA-2025:3989
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
eap8-jakarta-enterprise-concurrent-0:3.0.1-1.redhat_00001.1.el8eap
Fixed · RHSA-2025:3989
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
eap8-jsf-impl-0:4.0.11-1.redhat_00001.1.el8eap
Fixed · RHSA-2025:3989
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
eap8-reactive-streams-0:1.0.4-3.redhat_00004.1.el8eap
Fixed · RHSA-2025:3989
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
eap8-reactivex-rxjava-0:3.1.10-1.redhat_00001.1.el8eap
Fixed · RHSA-2025:3989
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
eap8-weld-core-0:5.1.5-1.Final_redhat_00001.1.el8eap
Fixed · RHSA-2025:3989
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
eap8-wildfly-0:8.0.7-3.GA_redhat_00004.1.el8eap
Fixed · RHSA-2025:3989
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
eap8-wildfly-elytron-0:2.2.9-1.Final_redhat_00001.1.el8eap
Fixed · RHSA-2025:3989
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
eap8-apache-commons-io-0:2.16.1-1.redhat_00001.1.el9eap
Fixed · RHSA-2025:3990
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
eap8-bouncycastle-0:1.80.0-1.redhat_00001.1.el9eap
Fixed · RHSA-2025:3990
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
eap8-eap-product-conf-parent-0:800.7.0-2.GA_redhat_00002.1.el9eap
Fixed · RHSA-2025:3990
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
eap8-hibernate-0:6.2.35-1.Final_redhat_00001.1.el9eap
Fixed · RHSA-2025:3990
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
eap8-ironjacamar-0:3.0.13-1.Final_redhat_00001.1.el9eap
Fixed · RHSA-2025:3990
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
eap8-jakarta-enterprise-concurrent-0:3.0.1-1.redhat_00001.1.el9eap
Fixed · RHSA-2025:3990
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
eap8-jsf-impl-0:4.0.11-1.redhat_00001.1.el9eap
Fixed · RHSA-2025:3990
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
eap8-reactive-streams-0:1.0.4-3.redhat_00004.1.el9eap
Fixed · RHSA-2025:3990
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
eap8-reactivex-rxjava-0:3.1.10-1.redhat_00001.1.el9eap
Fixed · RHSA-2025:3990
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
eap8-weld-core-0:5.1.5-1.Final_redhat_00001.1.el9eap
Fixed · RHSA-2025:3990
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
eap8-wildfly-0:8.0.7-3.GA_redhat_00004.1.el9eap
Fixed · RHSA-2025:3990
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
eap8-wildfly-elytron-0:2.2.9-1.Final_redhat_00001.1.el9eap
Fixed · RHSA-2025:3990
Red Hat Build of Keycloak
wildfly-server
Not affected
Red Hat Data Grid 8
wildfly-server
Will not fix
Red Hat Fuse 7
wildfly-server
Out of support scope
Red Hat JBoss Data Grid 7
wildfly-server
Out of support scope
Red Hat JBoss Enterprise Application Platform 7
wildfly-server
Will not fix
Red Hat JBoss Enterprise Application Platform Expansion Pack
wildfly-server
Not affected
Red Hat Process Automation 7
wildfly-server
Out of support scope
Red Hat Single Sign-On 7
wildfly-server
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat JBoss Enterprise Application Platform | org.wildfly.core/wildfly-server:15.0.45.Final-redhat-00001 | Fixed | RHSA-2025:3467 |
| Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 | eap7-netty-0:4.1.119-1.Final_redhat_00004.1.el8eap | Fixed | RHSA-2025:3465 |
| Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 | eap7-netty-transport-native-epoll-0:4.1.119-1.Final_redhat_00004.1.el8eap | Fixed | RHSA-2025:3465 |
| Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 | eap7-wildfly-0:7.4.21-3.GA_29548_redhat_00001.1.el8eap | Fixed | RHSA-2025:3465 |
| Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 | eap7-netty-0:4.1.119-1.Final_redhat_00004.1.el9eap | Fixed | RHSA-2025:3465 |
| Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 | eap7-netty-transport-native-epoll-0:4.1.119-1.Final_redhat_00004.1.el9eap | Fixed | RHSA-2025:3465 |
| Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 | eap7-wildfly-0:7.4.21-3.GA_29548_redhat_00001.1.el9eap | Fixed | RHSA-2025:3465 |
| Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7 | eap7-netty-0:4.1.119-1.Final_redhat_00004.1.el7eap | Fixed | RHSA-2025:3465 |
| Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7 | eap7-netty-transport-native-epoll-0:4.1.119-1.Final_redhat_00004.1.el7eap | Fixed | RHSA-2025:3465 |
| Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7 | eap7-wildfly-0:7.4.21-3.GA_29548_redhat_00001.1.el7eap | Fixed | RHSA-2025:3465 |
| Red Hat JBoss Enterprise Application Platform 7.4.22 | org.wildfly.core/wildfly-server:15.0.42.Final-redhat-00001 | Fixed | RHSA-2025:4552 |
| Red Hat JBoss Enterprise Application Platform 8 | wildfly-server | Fixed | RHSA-2025:3992 |
| Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 | eap8-apache-commons-io-0:2.16.1-1.redhat_00001.1.el8eap | Fixed | RHSA-2025:3989 |
| Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 | eap8-bouncycastle-0:1.80.0-1.redhat_00001.1.el8eap | Fixed | RHSA-2025:3989 |
| Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 | eap8-eap-product-conf-parent-0:800.7.0-2.GA_redhat_00002.1.el8eap | Fixed | RHSA-2025:3989 |
| Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 | eap8-hibernate-0:6.2.35-1.Final_redhat_00001.1.el8eap | Fixed | RHSA-2025:3989 |
| Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 | eap8-ironjacamar-0:3.0.13-1.Final_redhat_00001.1.el8eap | Fixed | RHSA-2025:3989 |
| Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 | eap8-jakarta-enterprise-concurrent-0:3.0.1-1.redhat_00001.1.el8eap | Fixed | RHSA-2025:3989 |
| Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 | eap8-jsf-impl-0:4.0.11-1.redhat_00001.1.el8eap | Fixed | RHSA-2025:3989 |
| Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 | eap8-reactive-streams-0:1.0.4-3.redhat_00004.1.el8eap | Fixed | RHSA-2025:3989 |
| Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 | eap8-reactivex-rxjava-0:3.1.10-1.redhat_00001.1.el8eap | Fixed | RHSA-2025:3989 |
| Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 | eap8-weld-core-0:5.1.5-1.Final_redhat_00001.1.el8eap | Fixed | RHSA-2025:3989 |
| Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 | eap8-wildfly-0:8.0.7-3.GA_redhat_00004.1.el8eap | Fixed | RHSA-2025:3989 |
| Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 | eap8-wildfly-elytron-0:2.2.9-1.Final_redhat_00001.1.el8eap | Fixed | RHSA-2025:3989 |
| Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | eap8-apache-commons-io-0:2.16.1-1.redhat_00001.1.el9eap | Fixed | RHSA-2025:3990 |
| Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | eap8-bouncycastle-0:1.80.0-1.redhat_00001.1.el9eap | Fixed | RHSA-2025:3990 |
| Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | eap8-eap-product-conf-parent-0:800.7.0-2.GA_redhat_00002.1.el9eap | Fixed | RHSA-2025:3990 |
| Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | eap8-hibernate-0:6.2.35-1.Final_redhat_00001.1.el9eap | Fixed | RHSA-2025:3990 |
| Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | eap8-ironjacamar-0:3.0.13-1.Final_redhat_00001.1.el9eap | Fixed | RHSA-2025:3990 |
| Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | eap8-jakarta-enterprise-concurrent-0:3.0.1-1.redhat_00001.1.el9eap | Fixed | RHSA-2025:3990 |
| Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | eap8-jsf-impl-0:4.0.11-1.redhat_00001.1.el9eap | Fixed | RHSA-2025:3990 |
| Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | eap8-reactive-streams-0:1.0.4-3.redhat_00004.1.el9eap | Fixed | RHSA-2025:3990 |
| Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | eap8-reactivex-rxjava-0:3.1.10-1.redhat_00001.1.el9eap | Fixed | RHSA-2025:3990 |
| Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | eap8-weld-core-0:5.1.5-1.Final_redhat_00001.1.el9eap | Fixed | RHSA-2025:3990 |
| Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | eap8-wildfly-0:8.0.7-3.GA_redhat_00004.1.el9eap | Fixed | RHSA-2025:3990 |
| Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | eap8-wildfly-elytron-0:2.2.9-1.Final_redhat_00001.1.el9eap | Fixed | RHSA-2025:3990 |
| Red Hat Build of Keycloak | wildfly-server | Not affected | n/a |
| Red Hat Data Grid 8 | wildfly-server | Will not fix | n/a |
| Red Hat Fuse 7 | wildfly-server | Out of support scope | n/a |
| Red Hat JBoss Data Grid 7 | wildfly-server | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform 7 | wildfly-server | Will not fix | n/a |
| Red Hat JBoss Enterprise Application Platform Expansion Pack | wildfly-server | Not affected | n/a |
| Red Hat Process Automation 7 | wildfly-server | Out of support scope | n/a |
| Red Hat Single Sign-On 7 | wildfly-server | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Red Hat statement
Red Hat has evaluated this issue and the attacker must be authenticated as a user that belongs to the "Monitor" or "Auditor" management groups. It requires previous privileges to jeopardize an environment.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (15)
- https://access.redhat.com/errata/RHSA-2025:3465 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:3467 vendor-advisoryx_refsource_REDHATIssue Tracking
- https://access.redhat.com/errata/RHSA-2025:3989 vendor-advisoryx_refsource_REDHATIssue Tracking
- https://access.redhat.com/errata/RHSA-2025:3990 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:3992 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:4548
- https://access.redhat.com/errata/RHSA-2025:4549
- https://access.redhat.com/errata/RHSA-2025:4550
- https://access.redhat.com/errata/RHSA-2025:4552 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2025-23367 vdb-entryx_refsource_REDHATVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2337620 issue-trackingx_refsource_REDHATVendor AdvisoryIssue Tracking
- https://github.com/advisories/GHSA-qr6x-62gq-4ccp AdvisoryThird Party Advisory
- https://github.com/wildfly/wildfly-core/security/advisories/GHSA-qr6x-62gq-4ccp
- https://nvd.nist.gov/vuln/detail/CVE-2025-23367
- https://www.cve.org/CVERecord?id=CVE-2025-23367
Change history (0)
No recorded changes yet.