Description
A flaw was found in wildfly-core. A management user could use the resolve-expression in the HAL Interface to read possible sensitive information from the Wildfly system. This issue could allow a malicious user to access the system and obtain possible sensitive information from the system.
Remediation
References
Related Vulnerabilities
Craft CMS Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2021-27903)
Atlassian Jira Missing Authorization Vulnerability (CVE-2019-15013)
Joomla! Core 2.5.x Cross-Site Scripting (2.5.0 - 2.5.9)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2014-0122)