VYPR

Maven package

org.wildfly.security/wildfly-elytron

pkg:maven/org.wildfly.security/wildfly-elytron

Vulnerabilities (5)

  • CVE-2024-12369MedDec 9, 2024
    affected >= 1.17.0.Final, < 2.2.9.Finalfixed 2.2.9.Final

    A vulnerability was found in OIDC-Client. When using the RH SSO OIDC adapter with EAP 7.x or when using the elytron-oidc-client subsystem with EAP 8.x, authorization code injection attacks can occur, allowing an attacker to inject a stolen authorization code into the attacker's o

  • CVE-2022-3143Jan 11, 2023
    affected < 1.15.15.Finalfixed 1.15.15.Final

    wildfly-elytron: possible timing attacks via use of unsafe comparator. A flaw was found in Wildfly-elytron. Wildfly-elytron uses java.util.Arrays.equals in several places, which is unsafe and vulnerable to timing attacks. To compare values securely, use java.security.MessageDiges

  • CVE-2021-3642Aug 5, 2021
    affected < 1.10.14fixed 1.10.14

    A flaw was found in Wildfly Elytron in versions prior to 1.10.14.Final, prior to 1.15.5.Final and prior to 1.16.1.Final where ScramServer may be susceptible to Timing Attack if enabled. The highest threat of this vulnerability is confidentiality.

  • CVE-2020-10714Sep 23, 2020
    affected < 1.11.4fixed 1.11.4

    A flaw was found in WildFly Elytron version 1.11.3.Final and before. When using WildFly Elytron FORM authentication with a session ID in the URL, an attacker could perform a session fixation attack. The highest threat from this vulnerability is to data confidentiality and integri

  • CVE-2020-1748Sep 16, 2020
    affected < 1.6.8fixed 1.6.8

    A flaw was found in all supported versions before wildfly-elytron-1.6.8.Final-redhat-00001, where the WildFlySecurityManager checks were bypassed when using custom security managers, resulting in an improper authorization. This flaw leads to information exposure by unauthenticate