VDB
CISA-2023-4503
CISA-2023-4503
PUBLISHED
CVSS 6.8 MEDIUM
Reported by redhat · Published February 6, 2024
An improper initialization vulnerability was found in Galleon. When using Galleon to provision custom EAP or EAP-XP servers, the servers are created unsecured. This issue could allow an attacker to access remote HTTP services available from the server.
Risk Scores
CVSS 3.1
6.8
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | EAP 7.4.14 | |
| Red Hat | Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 | 0:2.2.28-1.SP1_redhat_00001.1.el8eap |
| Red Hat | Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 | 0:7.4.14-5.GA_redhat_00002.1.el8eap |
| Red Hat | Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 | 0:2.2.28-1.SP1_redhat_00001.1.el9eap |
| Red Hat | Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 | 0:7.4.14-5.GA_redhat_00002.1.el9eap |
| Red Hat | Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7 | 0:2.2.28-1.SP1_redhat_00001.1.el7eap |
| Red Hat | Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7 | 0:7.4.14-5.GA_redhat_00002.1.el7eap |
| Red Hat | Red Hat JBoss Enterprise Application Platform Expansion Pack | |
| Red Hat | Red Hat JBoss Enterprise Application Platform Expansion Pack | |
| Red Hat | Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 | 0:2.2.28-1.SP1_redhat_00001.1.el9eap, * |
| Red Hat | Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 | 0:2.2.28-1.SP1_redhat_00001.1.el8eap, 0:2.2.28-1.SP1_redhat_00001.1.el8eap |
| Red Hat | Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7 | 0:2.2.28-1.SP1_redhat_00001.1.el7eap, 0:2.2.28-1.SP1_redhat_00001.1.el7eap |
| Red Hat | EAP 7.4.14 | |
| Red Hat | Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 | *, 0:7.4.14-5.GA_redhat_00002.1.el9eap |
| Red Hat | Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7 | *, 0:7.4.14-5.GA_redhat_00002.1.el7eap |
| Red Hat | Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 | *, 0:7.4.14-5.GA_redhat_00002.1.el8eap |
Timeline
- Feb 6, 2024 CVE Published
- Aug 2, 2024 CVE Updated
- Apr 26, 2026 Distribution Patch
- Apr 26, 2026 Distribution Patch
- Apr 26, 2026 Distribution Patch
- Apr 26, 2026 Distribution Patch
- Apr 26, 2026 Security Advisory
- Apr 26, 2026 Security Advisory
- Apr 26, 2026 Security Advisory
- Apr 26, 2026 Security Advisory
References
- RHSA-2023:7637 vendor-advisoryx_refsource_REDHAT
- RHSA-2023:7638 vendor-advisoryx_refsource_REDHAT
- RHSA-2023:7639 vendor-advisoryx_refsource_REDHAT
- RHSA-2023:7641 vendor-advisoryx_refsource_REDHAT
- vdb-entryx_refsource_REDHAT
- RHBZ#2184751 issue-trackingx_refsource_REDHAT