← Back

CVE-2025-23367

nvd nist
Published: Jan 30, 2025Modified: Jun 17, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Exploitability: 2.8 / Impact: 3.6
Source: secalert@redhat.com (Secondary)

Description

A flaw was found in the Wildfly Server Role Based Access Control (RBAC) provider. When authorization to control management operations is secured using the Role Based Access Control provider, a user without the required privileges can suspend or resume the server. A user with a Monitor or Auditor role is supposed to have only read access permissions and should not be able to suspend the server. The vulnerability is caused by the Suspend and Resume handlers not performing authorization checks to validate whether the current user has the required permissions to proceed with the action.

Affected (4)

2 products
Wildfly
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Redhat
From 7.4 to 7.4.21
From 8.0.0 to 8.0.7
Redhat
Before 27.0.1
Version 28.0.0 beta1

References (8)

Source: secalert@redhat.com
Issue Tracking
Source: secalert@redhat.com
Issue Tracking
Source: secalert@redhat.com
Vendor Advisory
Source: secalert@redhat.com
Vendor Advisory
Source: secalert@redhat.com
Third Party Advisory

Timeline

No history available yet.