org.wildfly.security:wildfly-elytron
Maven5 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.wildfly.security:wildfly-elytronpage 1 of 1
- CVE-2020-10714HIGHCVSS 7.5EG 7.5fixed in 1.11.42020-09-23
vulnerable: 1.0.0.Alpha1 ... 1.9.1.Final (171 versions)
A flaw was found in WildFly Elytron version 1.11.3.Final and before. When using WildFly Elytron FORM authentication with a session ID in the URL, an attacker could perform a session fixation attack. The highest threat from this vulnerabili…
- CVE-2020-1748HIGHCVSS 7.5EG 7.5fixed in 1.6.82020-09-16
vulnerable: 1.0.0.Alpha1 ... 1.6.7.Final (123 versions)
A flaw was found in all supported versions before wildfly-elytron-1.6.8.Final-redhat-00001, where the WildFlySecurityManager checks were bypassed when using custom security managers, resulting in an improper authorization. This flaw leads …
- CVE-2021-3642MEDIUMCVSS 5.3EG 5.3fixed in 1.10.14, 1.15.5 or 1.16.1, by version range2021-08-05
vulnerable: 1.16.0, 1.16.0.Final
A flaw was found in Wildfly Elytron in versions prior to 1.10.14.Final, prior to 1.15.5.Final and prior to 1.16.1.Final where ScramServer may be susceptible to Timing Attack if enabled. The highest threat of this vulnerability is confident…
- CVE-2022-3143HIGHCVSS 7.4EG 7.4fixed in 1.15.15.Final or 1.20.3.Final, by version range2023-01-13
vulnerable: 1.16.0.CR1 ... 1.20.2.Final (16 versions)
wildfly-elytron: possible timing attacks via use of unsafe comparator. A flaw was found in Wildfly-elytron. Wildfly-elytron uses java.util.Arrays.equals in several places, which is unsafe and vulnerable to timing attacks. To compare values…
- CVE-2024-12369MEDIUMCVSS 4.2EG 4.2fixed in 2.2.9.Final or 2.6.2.Final, by version range2024-12-09
vulnerable: 2.3.0.Final ... 2.6.1.Final (12 versions)
A vulnerability was found in OIDC-Client. When using the RH SSO OIDC adapter with EAP 7.x or when using the elytron-oidc-client subsystem with EAP 8.x, authorization code injection attacks can occur, allowing an attacker to inject a stolen…
Check whether org.wildfly.security:wildfly-elytron is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.wildfly.security:wildfly-elytron CVEs against the assets you own.
Book a Demo →