Description
A flaw was found in all supported versions before wildfly-elytron-1.6.8.Final-redhat-00001, where the WildFlySecurityManager checks were bypassed when using custom security managers, resulting in an improper authorization. This flaw leads to information exposure by unauthenticated access to secure resources.
Remediation
References
https://bugzilla.redhat.com/show_bug.cgi?id=1807707
https://security.netapp.com/advisory/ntap-20201001-0005/
Related Vulnerabilities
CVE-2020-27838 Vulnerability in maven package org.keycloak:keycloak-client-registration-api
CVE-2021-36161 Vulnerability in maven package org.apache.dubbo:dubbo-common
CVE-2023-35152 Vulnerability in maven package org.xwiki.platform:xwiki-platform-like-ui
CVE-2017-1000452 Vulnerability in npm package express-saml2
CVE-2023-45133 Vulnerability in maven package org.webjars.npm:babel-traverse