VDB

CVE-2024-10234

CVE-2024-10234 PUBLISHED CVSS 9.300000190734863 CRITICAL

JBoss Enterprise Application Platform ist eine skalierbare Plattform für Java-Anwendungen, inklusive JBoss Application Server, JBoss Hibernate und Boss Seam. Keycloak ermöglicht Single Sign-On mit Identity and Access Management für moderne Anwendungen und Dienste. Der WildFly Application Server ist ein Anwendungsserver nach dem Jakarta-EE-Standard.

EPSS 0.64% · 47.2th percentile

Risk Scores

CVSS 4.0
9.300000190734863
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
EPSS Score
0.64%
47.2th percentile

Affected Products

VendorProductVersions
Red HatRed Hat WildFly
Red HatRed Hat Single Sign On <7.6.12
Open SourceOpen Source Keycloak
Red HatRed Hat JBoss Enterprise Application Platform
Red HatRed Hat JBoss Enterprise Application Platform <7.4.23
Red HatRed Hat Enterprise Linux
Red HatRed Hat JBoss Enterprise Application Platform 8

Timeline

  • Oct 21, 2024 CVE Published
  • Oct 22, 2024 Coalition ESS Score
  • Oct 22, 2024 PoC Published
  • Oct 23, 2024 EPSS Score
  • Oct 23, 2024 Coalition ESS Score
  • Oct 30, 2024 Coalition ESS Score
  • Nov 10, 2024 EPSS Score
  • Nov 29, 2024 EPSS Score
  • Dec 18, 2024 EPSS Score
  • Jan 6, 2025 EPSS Score
  • Jan 24, 2025 EPSS Score
  • Feb 7, 2025 Coalition ESS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›