GHSA-wq8g-hm94-5rqq

    Dashboard / Vulnerabilities / GHSA-wq8g-hm94-5rqq

    GHSA-wq8g-hm94-5rqq

    Published: 23 Apr 2022Last Modified: 8 Nov 2023
    Aliases:

    Summary: JBoss AS may expose root content if excluded-contexts list is mismatched

    Details: JBoss AS 7 prior to 7.1.1 and mod_cluster do not handle default hostname in the same way, which can cause the excluded-contexts list to be mismatched and the root context to be exposed.

    Affected packages

    Package

    Name: org.jboss.as:jboss-as-server

    Purl: pkg:maven/org.jboss.as/jboss-as-server

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 7.0.0.Alpha1
    Fixed -7.1.1.Final

    Affected versions

    7.0.0.Alpha1
    7.0.0.Beta1
    7.0.0.Beta2
    7.0.0.Beta3
    7.0.0.CR1
    7.0.0.Final
    7.0.1.Final
    7.0.2.Final

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-wq8g-hm94-5rqq | CVE-DB