VDB

CVE-2021-3644

CVE-2021-3644 PUBLISHED CVSS 3.299999952316284 LOW

A flaw was found in wildfly-core in all versions. If a vault expression is in the form of a single attribute that contains multiple expressions, a user who was granted access to the management interface can potentially access a vault expression they should not be able to access and possibly retrieve the item which was stored in the vault. The highest threat from this vulnerability is data confidentiality and integrity.

EPSS 0.95% · 59.1th percentile

Risk Scores

CVSS 3.1
3.299999952316284
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N
EPSS Score
0.95%
59.1th percentile

Affected Products

VendorProductVersions
Bitnamiwildfly16.0.0
Bitnamiwildfly16.0.0

Timeline

  • Sep 8, 2021 CVE Published
  • Aug 27, 2022 EPSS Score
  • Oct 12, 2022 EPSS Score
  • Nov 27, 2022 EPSS Score
  • Jan 12, 2023 EPSS Score
  • Feb 26, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Apr 13, 2023 EPSS Score
  • May 29, 2023 EPSS Score
  • Jul 14, 2023 EPSS Score
  • Aug 29, 2023 EPSS Score
  • Oct 14, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›