Red Hat / Wildfly
21 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2025-23367 | Org.wildfly.core:wildfly-server: wildfly improper rbac permission | MEDIUM | 6.5 | Jan 30, 2025 |
| CVE-2022-1278 | WildFly: possible information disclosure | HIGH | 7.5 | Sep 13, 2022 |
| CVE-2021-3644 | wildfly-core: Invalid Sensitivity Classification of Vault Expression | LOW | 3.3 | Aug 26, 2022 |
| CVE-2022-0866 | wildfly: Wildfly management of EJB Session context returns wrong caller principal with Elytron Security enabled | MEDIUM | 5.3 | May 10, 2022 |
| CVE-2021-3503 | wildfly: Insufficient RBAC restrictions to metrics data | MEDIUM | 4.3 | Apr 18, 2022 |
| CVE-2020-1719 | Wildfly: EJBContext principal is not popped back after invoking another EJB using a different Security Domain | MEDIUM | 5.4 | Jun 7, 2021 |
| CVE-2020-14317 | wildfly: JBoss EAP-CD regression of CVE-2019-3805 | MEDIUM | 5.5 | Jun 2, 2021 |
| CVE-2021-3536 | wildfly: XSS via admin console when creating roles in domain mode | MEDIUM | 4.8 | May 20, 2021 |
| CVE-2020-27822 | wildfly: Potential Memory leak in Wildfly when using OpenTracing | MEDIUM | 5.9 | Dec 8, 2020 |
| CVE-2020-25640 | wildfly: resource adapter logs plaintext JMS password at warning level on connection error | MEDIUM | 5.3 | Nov 24, 2020 |
| CVE-2020-25689 | wildfly-core: memory leak in WildFly host-controller in domain mode while not able to reconnect to domain-controller | MEDIUM | 6.5 | Oct 30, 2020 |
| CVE-2020-10718 | wildfly: exposed setting of TCCL via the EmbeddedManagedProcess API | HIGH | 7.5 | Sep 16, 2020 |
| CVE-2020-14297 | wildfly: Some EJB transaction objects may get accumulated causing Denial of Service | MEDIUM | 6.5 | Jul 24, 2020 |
| CVE-2020-14307 | wildfly: EJB SessionOpenInvocations may not be removed properly after a response is received causing Denial of Service | MEDIUM | 6.5 | Jul 24, 2020 |
| CVE-2020-10740 | wildfly: unsafe deserialization in Wildfly Enterprise Java Beans | HIGH | 7.5 | Jun 22, 2020 |
| CVE-2019-14887 | wildfly: The 'enabled-protocols' value in legacy security is not respected if OpenSSL security provider is in use | CRITICAL | 9.1 | Mar 16, 2020 |
| CVE-2019-3894 | wildfly: wrong SecurityIdentity for EE concurrency threads that are reused | HIGH | 8.8 | May 3, 2019 |
| CVE-2019-3805 | wildfly: Race condition on PID file allows for termination of arbitrary processes by local users | MEDIUM | 4.7 | May 3, 2019 |
| CVE-2018-14627 | JBoss/WildFly: iiop does not honour strict transport confidentiality | MEDIUM | 5.9 | Sep 4, 2018 |
| CVE-2018-10683 | wildfly: Missing authentication in edfault installation without a security realm reference | CRITICAL | 9.8 | May 9, 2018 |
| CVE-2016-9589 | wildfly: ParseState headerValuesCache can be exploited to fill heap with garbage | HIGH | 7.5 | Mar 12, 2018 |
| CVE-2018-1047 | undertow: Path traversal in ServletResourceManager class | HIGH | 8.6 | Jan 24, 2018 |
Showing 1 to 21 of 21 CVEs