A flaw was found when an OpenSSL security provider is used with Wildfly, the 'enabled-protocols' value in the Wildfly configuration isn't honored. An attacker could target the traffic sent from Wildfly and downgrade the connection to a weaker version of TLS, potentially breaking the encryption. This could lead to a leak of the data being passed over the network. Wildfly version 7.2.0.GA, 7.2.3.GA and 7.2.5.CR2 are believed to be vulnerable.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NRed Hat Jboss Data Grid
APPRedhat7.0.0Red Hat Jboss Enterprise Application Platform
APPRedhat7.0.0Red Hat Jboss Fuse
APPRedhat7.0.0Red Hat Openshift Application Runtimes
APPRedhatall versionsRed Hat Single Sign On
APPRedhat7.0Red Hat Wildfly
APPRedhat7.2.07.2.37.2.5
Related vulnerabilities
RCE przez niebezpieczną deserializację w JBoss HTTP Invoker (EAP 5.2)
Brak walidacji nagłówka Host w serwerze Undertow HTTP
XSS w Keycloak — podatność w obsłudze SAML/OIDC umożliwia wykonanie złośliwych skryptów
RCE poprzez deserializację JNDI w jackson-databind (commons-configuration)
Netty: nieprawidłowe parsowanie nagłówków HTTP bez dwukropka (HTTP Request Smuggling)