VDB
CVE-2025-23367
CVE-2025-23367
PUBLISHED
CVSS 6.5 MEDIUM
A flaw was found in the Wildfly Server Role Based Access Control (RBAC) provider. When authorization to control management operations is secured using the Role Based Access Control provider, a user without the required privileges can suspend or resume the server. A user with a Monitor or Auditor role is supposed to have only read access permissions and should not be able to suspend the server. The vulnerability is caused by the Suspend and Resume handlers not performing authorization checks to validate whether the current user has the required permissions to proceed with the action.
EPSS 0.77% · 54.1th percentile
Risk Scores
CVSS 3.1
6.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS Score
0.77%
54.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bitnami | wildfly | 0, 28.0.0 |
| Bitnami | wildfly | 28.0.0, 0 |
Timeline
- Jan 21, 1970 Distribution Patch
- Jan 21, 1970 Distribution Patch
- Jan 21, 1970 Distribution Patch
- Jan 21, 1970 Distribution Patch
- Jan 21, 1970 Security Advisory
- Jan 21, 1970 Security Advisory
- Jan 21, 1970 Security Advisory
- Jan 21, 1970 Security Advisory
- Jan 30, 2025 CVE Published
- Jan 31, 2025 EPSS Score
- Feb 1, 2025 Coalition ESS Score
- Feb 16, 2025 EPSS Score
References
- https://access.redhat.com/errata/RHSA-2025:3467 advisory
- https://access.redhat.com/errata/RHSA-2025:3989 advisory
- https://access.redhat.com/security/cve/CVE-2025-23367 advisory
- https://access.redhat.com/errata/RHSA-2025:3990 advisory
- https://access.redhat.com/errata/RHSA-2025:3992 advisory
- https://access.redhat.com/errata/RHSA-2025:3465 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2337620 url
- https://github.com/advisories/GHSA-qr6x-62gq-4ccp url
- https://nvd.nist.gov/vuln/detail/CVE-2025-23367 url