CVE-2021-3642
5.3
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 1.6 / Impact: 3.6
Source: NVD
Description
A flaw was found in Wildfly Elytron in versions prior to 1.10.14.Final, prior to 1.15.5.Final and prior to 1.16.1.Final where ScramServer may be susceptible to Timing Attack if enabled. The highest threat of this vulnerability is confidentiality.
Affected (15)
Products: Redhat: Wildfly Elytron, Build Of Quarkus, Codeready Studio, Data Grid, Descision Manager, Integration Camel K, Integration Camel Quarkus, Jboss Enterprise Application Platform, Jboss Enterprise Application Platform Expansion Pack, Jboss Fuse, Openshift Application Runtimes, Process Automation · Quarkus: Quarkus
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.10.14 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| All versions | |
| Version 12.0 | |
| Version 8.0 | |
| Version 7.0 | |
| All versions | |
| All versions | |
| Version 7.0.0 | |
| All versions | |
| Version 7.0.0 | |
| All versions | |
| Version 7.0 |
References (2)
Source: secalert@redhat.com
Issue TrackingVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingVendor Advisory
Timeline
No history available yet.