Description
A flaw was found in Wildfly. An incorrect JBOSS_LOCAL_USER challenge location when using the elytron configuration may lead to JBOSS_LOCAL_USER access to all users on the machine. The highest threat from this vulnerability is to confidentiality, integrity, and availability. This flaw affects wildfly-core versions prior to 17.0.
Remediation
References
Related Vulnerabilities
SharePoint CVE-2023-21716 Vulnerability (CVE-2023-21716)
MediaWiki Exposure of Resource to Wrong Sphere Vulnerability (CVE-2021-30153)
WordPress Plugin 404 to 301-Redirect, Log and Notify 404 Errors Cloaking (2.2.9)
WordPress 5.4.x Multiple Vulnerabilities (5.4 - 5.4.13)
WordPress Plugin SyntaxHighlighter Evolved Cross-Site Scripting (3.5.0)