GHSA-qr6x-62gq-4ccp
MEDIUMCVE-2025-23367A flaw was found in the Wildfly Server Role Based Access Control (RBAC) provider. When authorization to control management operations is secured using the Role Based Access Control provider, a user without the required privileges can suspend or resume the server. A user with a Monitor or Auditor role is supposed to have only read access permissions and should not be able to suspend the server. The
- Affected
- >=0, <27.0.1, >=28.0.0, <31.0.1
- Fixed in
- 27.0.1.Final
- Weakness
- CWE-284
- Published
- 2025-01-31
- Source
- github