GHSA-p9xf-3rm3-qh2h
GitHub Security Advisory
Wildfly-Core user account mismanagement
✓ GitHub Reviewed
HIGH
Has CVE
Advisory Details
A flaw was found in Wildfly. An incorrect JBOSS_LOCAL_USER challenge location when using the elytron configuration may lead to JBOSS_LOCAL_USER access to all users on the machine. The highest threat from this vulnerability is to confidentiality, integrity, and availability. This flaw affects wildfly-core versions prior to 17.0.
Affected Packages
Maven
org.wildfly.core:wildfly-core-parent
Affected versions:
0
(fixed in 17.0)
Related CVEs
Key Information
7.5
/10
Dataset
Last updated: August 3, 2025 6:48 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.