Risk | Medium |
Patch available | YES |
Number of vulnerabilities | 4 |
CVE-ID | CVE-2023-4759 CVE-2023-35887 CVE-2023-4043 CVE-2023-48795 |
CWE-ID | CWE-59 CWE-61 CWE-834 CWE-326 |
Exploitation vector | Network |
Public exploit | Public exploit code for vulnerability #4 is available. |
Vulnerable software |
JBoss Enterprise Application Platform Server applications / Application servers eap8-wildfly (Red Hat package) Operating systems & Components / Operating system package or component eap8-parsson (Red Hat package) Operating systems & Components / Operating system package or component eap8-lucene-solr (Red Hat package) Operating systems & Components / Operating system package or component eap8-log4j (Red Hat package) Operating systems & Components / Operating system package or component eap8-eclipse-jgit (Red Hat package) Operating systems & Components / Operating system package or component eap8-apache-sshd (Red Hat package) Operating systems & Components / Operating system package or component |
Vendor | Red Hat Inc. |
Security Bulletin
This security bulletin contains information about 4 vulnerabilities.
EUVDB-ID: #VU81948
Risk: Medium
CVSSv4.0: 4.8 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2023-4759
CWE-ID:
CWE-59 - Improper Link Resolution Before File Access ('Link Following')
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to overwrite files on the system.
The vulnerability exists due to an insecure link following. A remote attacker can place a specially crafted symbolic link into the repository, trick the victim into cloning it and overwrite arbitrary files on the system.
Install updates from vendor's website.
JBoss Enterprise Application Platform: 8.0
eap8-wildfly (Red Hat package): before 8.0.1-3.GA_redhat_00002.1.el8eap
eap8-parsson (Red Hat package): before 1.1.5-1.redhat_00001.1.el8eap
eap8-lucene-solr (Red Hat package): before 8.11.2-2.redhat_00001.1.el8eap
eap8-log4j (Red Hat package): before 2.19.0-2.redhat_00001.1.el8eap
eap8-eclipse-jgit (Red Hat package): before 6.6.1.202309021850-1.r_redhat_00001.1.el8eap
eap8-apache-sshd (Red Hat package): before 2.12.0-1.redhat_00001.1.el8eap
CPE2.3https://access.redhat.com/errata/RHSA-2024:1192
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU81427
Risk: Low
CVSSv4.0: 1.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2023-35887
CWE-ID:
CWE-61 - UNIX Symbolic Link (Symlink) Following
Exploit availability: No
DescriptionThe vulnerability allows a remote user to gain access to sensitive information.
The vulnerability exists due to insecure symlink following that lead to files outside the RootedFileSystem. A remote user can identify presence of files on the system.
Install updates from vendor's website.
JBoss Enterprise Application Platform: 8.0
eap8-wildfly (Red Hat package): before 8.0.1-3.GA_redhat_00002.1.el8eap
eap8-parsson (Red Hat package): before 1.1.5-1.redhat_00001.1.el8eap
eap8-lucene-solr (Red Hat package): before 8.11.2-2.redhat_00001.1.el8eap
eap8-log4j (Red Hat package): before 2.19.0-2.redhat_00001.1.el8eap
eap8-eclipse-jgit (Red Hat package): before 6.6.1.202309021850-1.r_redhat_00001.1.el8eap
eap8-apache-sshd (Red Hat package): before 2.12.0-1.redhat_00001.1.el8eap
CPE2.3https://access.redhat.com/errata/RHSA-2024:1192
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU85304
Risk: Medium
CVSSv4.0: 6.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2023-4043
CWE-ID:
CWE-834 - Excessive Iteration
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to built-in support for parsing numbers with large scale in Java has a number of edge cases where the input text of a number can lead to much larger processing time than one would expect. A remote attacker can trigger excessive iteration and perform a denial of service (DoS) attack.
MitigationInstall updates from vendor's website.
JBoss Enterprise Application Platform: 8.0
eap8-wildfly (Red Hat package): before 8.0.1-3.GA_redhat_00002.1.el8eap
eap8-parsson (Red Hat package): before 1.1.5-1.redhat_00001.1.el8eap
eap8-lucene-solr (Red Hat package): before 8.11.2-2.redhat_00001.1.el8eap
eap8-log4j (Red Hat package): before 2.19.0-2.redhat_00001.1.el8eap
eap8-eclipse-jgit (Red Hat package): before 6.6.1.202309021850-1.r_redhat_00001.1.el8eap
eap8-apache-sshd (Red Hat package): before 2.12.0-1.redhat_00001.1.el8eap
CPE2.3https://access.redhat.com/errata/RHSA-2024:1192
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU84537
Risk: Low
CVSSv4.0: 2.9 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/U:Clear]
CVE-ID: CVE-2023-48795
CWE-ID:
CWE-326 - Inadequate Encryption Strength
Exploit availability: Yes
DescriptionThe vulnerability allows a remote attacker to perform MitM attack.
The vulnerability exists due to incorrect implementation of the SSH Binary Packet Protocol (BPP), which mishandles the handshake phase and the use of sequence numbers. A remote attacker can perform MitM attack and delete the SSH2_MSG_EXT_INFO message sent before authentication starts, allowing the attacker to disable a subset of the keystroke timing obfuscation features introduced in OpenSSH 9.5.
The vulnerability was dubbed "Terrapin attack" and it affects both client and server implementations.
Install updates from vendor's website.
JBoss Enterprise Application Platform: 8.0
eap8-wildfly (Red Hat package): before 8.0.1-3.GA_redhat_00002.1.el8eap
eap8-parsson (Red Hat package): before 1.1.5-1.redhat_00001.1.el8eap
eap8-lucene-solr (Red Hat package): before 8.11.2-2.redhat_00001.1.el8eap
eap8-log4j (Red Hat package): before 2.19.0-2.redhat_00001.1.el8eap
eap8-eclipse-jgit (Red Hat package): before 6.6.1.202309021850-1.r_redhat_00001.1.el8eap
eap8-apache-sshd (Red Hat package): before 2.12.0-1.redhat_00001.1.el8eap
CPE2.3https://access.redhat.com/errata/RHSA-2024:1192
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability. However, proof of concept for this vulnerability is available.