#VU54938 Improper access control in Wildfly Core - CVE-2021-3644
Published: July 19, 2021
Wildfly Core
Red Hat Inc.
Description
The vulnerability allows a remote user to gain unauthorized access to sensitive information.
The vulnerability exists due to improper access restrictions to vault expressions. A remote user with access to management interface can can access restricted vault and retrieve items stored in the vault, if a vault expression is in the form of a single attribute that contains multiple expressions.