A flaw was found in JwtValidator.resolvePublicKey
in JBoss EAP, where the validator checks jku and sends a HTTP request. During this process, no whitelisting or other filtering behavior is performed on the destination URL address, which may result in a server-side request forgery (SSRF) vulnerability.
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Red Hat JBoss Enterprise Application Platform 7 | RedHat | eap | * |
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 | RedHat | eap7-apache-cxf-0:3.5.8-1.redhat_00001.1.el8eap | * |
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 | RedHat | eap7-hal-console-0:3.3.22-1.Final_redhat_00001.1.el8eap | * |
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 | RedHat | eap7-infinispan-0:11.0.19-2.Final_redhat_00001.1.el8eap | * |
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 | RedHat | eap7-jboss-ejb-client-0:4.0.54-3.Final_redhat_00001.1.el8eap | * |
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 | RedHat | eap7-jboss-jsf-api_2.3_spec-0:3.0.0-8.SP08_redhat_00001.1.el8eap | * |
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 | RedHat | eap7-jboss-metadata-0:13.5.0-1.Final_redhat_00001.1.el8eap | * |
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 | RedHat | eap7-jboss-modules-0:1.12.3-3.Final_redhat_00001.1.el8eap | * |
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 | RedHat | eap7-jboss-server-migration-0:1.10.0-36.Final_redhat_00035.1.el8eap | * |
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 | RedHat | eap7-undertow-0:2.2.32-1.SP1_redhat_00001.1.el8eap | * |
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 | RedHat | eap7-wildfly-0:7.4.17-2.GA_redhat_00002.1.el8eap | * |
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 | RedHat | eap7-wildfly-discovery-0:1.2.4-1.Final_redhat_00001.1.el8eap | * |
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 | RedHat | eap7-wildfly-elytron-0:1.15.23-2.Final_redhat_00001.1.el8eap | * |
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 | RedHat | eap7-wildfly-http-client-0:1.1.17-1.Final_redhat_00002.1.el8eap | * |
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 | RedHat | eap7-wildfly-transaction-client-0:1.1.19-1.Final_redhat_00001.1.el8eap | * |
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 | RedHat | eap7-wss4j-0:2.4.3-1.redhat_00001.1.el8eap | * |
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 | RedHat | eap7-xml-security-0:2.3.4-1.redhat_00002.1.el8eap | * |
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 | RedHat | eap7-apache-cxf-0:3.5.8-1.redhat_00001.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 | RedHat | eap7-hal-console-0:3.3.22-1.Final_redhat_00001.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 | RedHat | eap7-infinispan-0:11.0.19-2.Final_redhat_00001.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 | RedHat | eap7-jboss-ejb-client-0:4.0.54-3.Final_redhat_00001.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 | RedHat | eap7-jboss-jsf-api_2.3_spec-0:3.0.0-8.SP08_redhat_00001.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 | RedHat | eap7-jboss-metadata-0:13.5.0-1.Final_redhat_00001.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 | RedHat | eap7-jboss-modules-0:1.12.3-3.Final_redhat_00001.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 | RedHat | eap7-jboss-server-migration-0:1.10.0-36.Final_redhat_00035.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 | RedHat | eap7-undertow-0:2.2.32-1.SP1_redhat_00001.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 | RedHat | eap7-wildfly-0:7.4.17-2.GA_redhat_00002.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 | RedHat | eap7-wildfly-discovery-0:1.2.4-1.Final_redhat_00001.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 | RedHat | eap7-wildfly-elytron-0:1.15.23-2.Final_redhat_00001.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 | RedHat | eap7-wildfly-http-client-0:1.1.17-1.Final_redhat_00002.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 | RedHat | eap7-wildfly-transaction-client-0:1.1.19-1.Final_redhat_00001.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 | RedHat | eap7-wss4j-0:2.4.3-1.redhat_00001.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 | RedHat | eap7-xml-security-0:2.3.4-1.redhat_00002.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7 | RedHat | eap7-wildfly-elytron-0:1.15.23-2.Final_redhat_00001.1.el7eap | * |
Red Hat JBoss Enterprise Application Platform 8 | RedHat | eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 | RedHat | eap8-elytron-web-0:4.0.1-1.Final_redhat_00001.1.el8eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 | RedHat | eap8-wildfly-elytron-0:2.2.4-2.SP01_redhat_00001.1.el8eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | RedHat | eap8-elytron-web-0:4.0.1-1.Final_redhat_00001.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | RedHat | eap8-wildfly-elytron-0:2.2.4-2.SP01_redhat_00001.1.el9eap | * |