CVE-2016-0793

Description

An incomplete-blacklist flaw was found in the blacklisting of URLs in Wildfly. A remote, unauthenticated user could exploit this flaw to expose sensitive files.

Statement

Only Wildfly application servers running on Windows operating systems are affected; no versions of Red Hat JBoss EAP or layered products are affected.

Understanding the Weakness (CWE)

Access Control

Technical Impact: Bypass Protection Mechanism

Attackers may be able to find other malicious inputs that were not expected by the developer, allowing them to bypass the intended protection mechanism.

Acknowledgements

Red Hat would like to thank Tal Solomon (Palantir Security) for reporting this issue.

Frequently Asked Questions

Want to get errata notifications? Sign up here.