漏洞标题
Org.wildfly.core:wildfly-server: WildFly RBAC权限配置不当漏洞
漏洞描述信息
在Wildfly Server的角色基础访问控制(RBAC)提供程序中发现了一个漏洞。当使用角色基础访问控制提供程序来保护对管理操作的授权时,没有所需权限的用户可以暂停或恢复服务器。具有监控或审计角色的用户应仅具有读取访问权限,不应能够暂停服务器。该漏洞是由暂停和恢复处理程序未执行授权检查来验证当前用户是否具有执行操作所需权限引起的。
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
漏洞类别
授权机制缺失
漏洞标题
Org.wildfly.core:wildfly-server: wildfly improper rbac permission
漏洞描述信息
A flaw was found in the Wildfly Server Role Based Access Control (RBAC) provider. When authorization to control management operations is secured using the Role Based Access Control provider, a user without the required privileges can suspend or resume the server. A user with a Monitor or Auditor role is supposed to have only read access permissions and should not be able to suspend the server.
The vulnerability is caused by the Suspend and Resume handlers not performing authorization checks to validate whether the current user has the required permissions to proceed with the action.
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
漏洞类别
访问控制不恰当