SB2025032404 - Multiple vulnerabilities in WildFly
Published: March 24, 2025 Updated: March 24, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 secuirty vulnerabilities.
1) Stored cross-site scripting (CVE-ID: CVE-2024-10234)
The disclosed vulnerability allows a remote user to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data. A remote user can inject and execute arbitrary HTML and script code in the user's browser.
2) Creation of temporary file with insecure permissions (CVE-ID: CVE-2024-51127)
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to an error within the createTempFile method. A local user can overwrite arbitrary files on the system and potentially escalate privileges.
Remediation
Install update from vendor's website.