Description
A flaw was found in all supported versions before wildfly-elytron-1.6.8.Final-redhat-00001, where the WildFlySecurityManager checks were bypassed when using custom security managers, resulting in an improper authorization. This flaw leads to information exposure by unauthenticated access to secure resources.
Remediation
References
https://bugzilla.redhat.com/show_bug.cgi?id=1807707
https://security.netapp.com/advisory/ntap-20201001-0005/
Related Vulnerabilities
CVE-2020-11973 Vulnerability in maven package org.apache.camel:camel-netty
CVE-2022-31777 Vulnerability in maven package org.apache.spark:spark-core_2.12
CVE-2022-25858 Vulnerability in maven package org.webjars.npm:terser
CVE-2023-46651 Vulnerability in maven package io.jenkins.plugins:warnings-ng
CVE-2020-13942 Vulnerability in maven package org.apache.unomi:unomi-common