CVE Vulnerabilities

CVE-2024-1233

Server-Side Request Forgery (SSRF)

Published: Apr 09, 2024 | Modified: Jun 04, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
7.3 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Ubuntu

A flaw was found in JwtValidator.resolvePublicKey in JBoss EAP, where the validator checks jku and sends a HTTP request. During this process, no whitelisting or other filtering behavior is performed on the destination URL address, which may result in a server-side request forgery (SSRF) vulnerability.

Weakness

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Affected Software

Name Vendor Start Version End Version
Red Hat JBoss Enterprise Application Platform 7 RedHat eap *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 RedHat eap7-apache-cxf-0:3.5.8-1.redhat_00001.1.el8eap *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 RedHat eap7-hal-console-0:3.3.22-1.Final_redhat_00001.1.el8eap *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 RedHat eap7-infinispan-0:11.0.19-2.Final_redhat_00001.1.el8eap *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 RedHat eap7-jboss-ejb-client-0:4.0.54-3.Final_redhat_00001.1.el8eap *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 RedHat eap7-jboss-jsf-api_2.3_spec-0:3.0.0-8.SP08_redhat_00001.1.el8eap *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 RedHat eap7-jboss-metadata-0:13.5.0-1.Final_redhat_00001.1.el8eap *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 RedHat eap7-jboss-modules-0:1.12.3-3.Final_redhat_00001.1.el8eap *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 RedHat eap7-jboss-server-migration-0:1.10.0-36.Final_redhat_00035.1.el8eap *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 RedHat eap7-undertow-0:2.2.32-1.SP1_redhat_00001.1.el8eap *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 RedHat eap7-wildfly-0:7.4.17-2.GA_redhat_00002.1.el8eap *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 RedHat eap7-wildfly-discovery-0:1.2.4-1.Final_redhat_00001.1.el8eap *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 RedHat eap7-wildfly-elytron-0:1.15.23-2.Final_redhat_00001.1.el8eap *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 RedHat eap7-wildfly-http-client-0:1.1.17-1.Final_redhat_00002.1.el8eap *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 RedHat eap7-wildfly-transaction-client-0:1.1.19-1.Final_redhat_00001.1.el8eap *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 RedHat eap7-wss4j-0:2.4.3-1.redhat_00001.1.el8eap *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 RedHat eap7-xml-security-0:2.3.4-1.redhat_00002.1.el8eap *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 RedHat eap7-apache-cxf-0:3.5.8-1.redhat_00001.1.el9eap *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 RedHat eap7-hal-console-0:3.3.22-1.Final_redhat_00001.1.el9eap *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 RedHat eap7-infinispan-0:11.0.19-2.Final_redhat_00001.1.el9eap *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 RedHat eap7-jboss-ejb-client-0:4.0.54-3.Final_redhat_00001.1.el9eap *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 RedHat eap7-jboss-jsf-api_2.3_spec-0:3.0.0-8.SP08_redhat_00001.1.el9eap *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 RedHat eap7-jboss-metadata-0:13.5.0-1.Final_redhat_00001.1.el9eap *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 RedHat eap7-jboss-modules-0:1.12.3-3.Final_redhat_00001.1.el9eap *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 RedHat eap7-jboss-server-migration-0:1.10.0-36.Final_redhat_00035.1.el9eap *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 RedHat eap7-undertow-0:2.2.32-1.SP1_redhat_00001.1.el9eap *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 RedHat eap7-wildfly-0:7.4.17-2.GA_redhat_00002.1.el9eap *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 RedHat eap7-wildfly-discovery-0:1.2.4-1.Final_redhat_00001.1.el9eap *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 RedHat eap7-wildfly-elytron-0:1.15.23-2.Final_redhat_00001.1.el9eap *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 RedHat eap7-wildfly-http-client-0:1.1.17-1.Final_redhat_00002.1.el9eap *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 RedHat eap7-wildfly-transaction-client-0:1.1.19-1.Final_redhat_00001.1.el9eap *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 RedHat eap7-wss4j-0:2.4.3-1.redhat_00001.1.el9eap *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 RedHat eap7-xml-security-0:2.3.4-1.redhat_00002.1.el9eap *
Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7 RedHat eap7-wildfly-elytron-0:1.15.23-2.Final_redhat_00001.1.el7eap *
Red Hat JBoss Enterprise Application Platform 8 RedHat eap *
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 RedHat eap8-elytron-web-0:4.0.1-1.Final_redhat_00001.1.el8eap *
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 RedHat eap8-wildfly-elytron-0:2.2.4-2.SP01_redhat_00001.1.el8eap *
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 RedHat eap8-elytron-web-0:4.0.1-1.Final_redhat_00001.1.el9eap *
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 RedHat eap8-wildfly-elytron-0:2.2.4-2.SP01_redhat_00001.1.el9eap *

References