CVE Vulnerabilities

CVE-2024-1233

Server-Side Request Forgery (SSRF)

Published: Apr 09, 2024 | Modified: Oct 24, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
7.3 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Ubuntu
root.io logo minimus.io logo echo.ai logo

A flaw was found in JwtValidator.resolvePublicKey in JBoss EAP, where the validator checks jku and sends a HTTP request. During this process, no whitelisting or other filtering behavior is performed on the destination URL address, which may result in a server-side request forgery (SSRF) vulnerability.

Weakness

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Affected Software

NameVendorStart VersionEnd Version
Red Hat JBoss Enterprise Application PlatformRedHatorg.wildfly.security/wildfly-elytron:1.15.23.Final-redhat-00001*
Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7RedHateap7-glassfish-el-0:3.0.1-4.b08_redhat_00005.1.ep7.el7*
Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7RedHateap7-hibernate-0:5.1.17-3.Final_redhat_00004.1.ep7.el7*
Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7RedHateap7-jackson-databind-0:2.8.11.6-3.SP1_redhat_00003.1.ep7.el7*
Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7RedHateap7-jboss-ejb-client-0:4.0.12-1.Final_redhat_00002.1.ep7.el7*
Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7RedHateap7-netty-0:4.1.63-2.Final_redhat_00003.1.ep7.el7*
Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7RedHateap7-undertow-0:1.4.18-16.SP14_redhat_00001.1.ep7.el7*
Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7RedHateap7-wildfly-0:7.1.11-4.GA_redhat_00002.1.ep7.el7*
Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7RedHateap7-wildfly-elytron-0:1.1.14-1.Final_redhat_00001.1.ep7.el7*
Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7RedHateap7-wildfly-http-client-0:1.0.21-1.Final_redhat_00001.1.ep7.el7*
Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7RedHateap7-wildfly-naming-client-0:1.0.13-1.Final_redhat_00001.1.ep7.el7*
Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7RedHateap7-wildfly-openssl-0:1.0.12-1.Final_redhat_00001.1.ep7.el7*
Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7RedHateap7-wildfly-openssl-linux-0:1.0.12-6.Final_redhat_00001.1.ep7.el7*
Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7RedHateap7-jackson-annotations-0:2.10.4-3.redhat_00006.1.el7eap*
Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7RedHateap7-jackson-core-0:2.10.4-3.redhat_00006.1.el7eap*
Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7RedHateap7-jackson-databind-0:2.10.4-5.redhat_00006.1.el7eap*
Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7RedHateap7-jackson-jaxrs-providers-0:2.10.4-3.redhat_00006.1.el7eap*
Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7RedHateap7-jackson-modules-base-0:2.10.4-5.redhat_00006.1.el7eap*
Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7RedHateap7-jackson-modules-java8-0:2.10.4-2.redhat_00006.1.el7eap*
Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7RedHateap7-jboss-server-migration-0:1.7.2-16.Final_redhat_00017.1.el7eap*
Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7RedHateap7-netty-0:4.1.63-5.Final_redhat_00003.1.el7eap*
Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7RedHateap7-undertow-0:2.0.41-4.SP5_redhat_00001.1.el7eap*
Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7RedHateap7-wildfly-0:7.3.14-3.GA_redhat_00002.1.el7eap*
Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7RedHateap7-wildfly-elytron-0:1.10.17-1.Final_redhat_00001.1.el7eap*
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8RedHateap7-apache-cxf-0:3.5.8-1.redhat_00001.1.el8eap*
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8RedHateap7-hal-console-0:3.3.22-1.Final_redhat_00001.1.el8eap*
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8RedHateap7-infinispan-0:11.0.19-2.Final_redhat_00001.1.el8eap*
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8RedHateap7-jboss-ejb-client-0:4.0.54-3.Final_redhat_00001.1.el8eap*
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8RedHateap7-jboss-jsf-api_2.3_spec-0:3.0.0-8.SP08_redhat_00001.1.el8eap*
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8RedHateap7-jboss-metadata-0:13.5.0-1.Final_redhat_00001.1.el8eap*
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8RedHateap7-jboss-modules-0:1.12.3-3.Final_redhat_00001.1.el8eap*
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8RedHateap7-jboss-server-migration-0:1.10.0-36.Final_redhat_00035.1.el8eap*
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8RedHateap7-undertow-0:2.2.32-1.SP1_redhat_00001.1.el8eap*
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8RedHateap7-wildfly-0:7.4.17-2.GA_redhat_00002.1.el8eap*
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8RedHateap7-wildfly-discovery-0:1.2.4-1.Final_redhat_00001.1.el8eap*
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8RedHateap7-wildfly-elytron-0:1.15.23-2.Final_redhat_00001.1.el8eap*
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8RedHateap7-wildfly-http-client-0:1.1.17-1.Final_redhat_00002.1.el8eap*
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8RedHateap7-wildfly-transaction-client-0:1.1.19-1.Final_redhat_00001.1.el8eap*
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8RedHateap7-wss4j-0:2.4.3-1.redhat_00001.1.el8eap*
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8RedHateap7-xml-security-0:2.3.4-1.redhat_00002.1.el8eap*
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9RedHateap7-apache-cxf-0:3.5.8-1.redhat_00001.1.el9eap*
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9RedHateap7-hal-console-0:3.3.22-1.Final_redhat_00001.1.el9eap*
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9RedHateap7-infinispan-0:11.0.19-2.Final_redhat_00001.1.el9eap*
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9RedHateap7-jboss-ejb-client-0:4.0.54-3.Final_redhat_00001.1.el9eap*
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9RedHateap7-jboss-jsf-api_2.3_spec-0:3.0.0-8.SP08_redhat_00001.1.el9eap*
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9RedHateap7-jboss-metadata-0:13.5.0-1.Final_redhat_00001.1.el9eap*
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9RedHateap7-jboss-modules-0:1.12.3-3.Final_redhat_00001.1.el9eap*
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9RedHateap7-jboss-server-migration-0:1.10.0-36.Final_redhat_00035.1.el9eap*
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9RedHateap7-undertow-0:2.2.32-1.SP1_redhat_00001.1.el9eap*
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9RedHateap7-wildfly-0:7.4.17-2.GA_redhat_00002.1.el9eap*
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9RedHateap7-wildfly-discovery-0:1.2.4-1.Final_redhat_00001.1.el9eap*
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9RedHateap7-wildfly-elytron-0:1.15.23-2.Final_redhat_00001.1.el9eap*
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9RedHateap7-wildfly-http-client-0:1.1.17-1.Final_redhat_00002.1.el9eap*
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9RedHateap7-wildfly-transaction-client-0:1.1.19-1.Final_redhat_00001.1.el9eap*
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9RedHateap7-wss4j-0:2.4.3-1.redhat_00001.1.el9eap*
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9RedHateap7-xml-security-0:2.3.4-1.redhat_00002.1.el9eap*
Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7RedHateap7-wildfly-elytron-0:1.15.23-2.Final_redhat_00001.1.el7eap*
Red Hat JBoss Enterprise Application Platform 8RedHateap*
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8RedHateap8-elytron-web-0:4.0.1-1.Final_redhat_00001.1.el8eap*
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8RedHateap8-wildfly-elytron-0:2.2.4-2.SP01_redhat_00001.1.el8eap*
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9RedHateap8-elytron-web-0:4.0.1-1.Final_redhat_00001.1.el9eap*
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9RedHateap8-wildfly-elytron-0:2.2.4-2.SP01_redhat_00001.1.el9eap*

References