CVE-2021-3717: Wildfly-Core user account mismanagement
7.8
CVSS Score
3.1
Basic Information
CVE ID
GHSA ID
EPSS Score
0.06387%
CWE
Published
5/25/2022
Updated
1/31/2023
KEV Status
No
Technology
Java
Technical Details
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.wildfly.core:wildfly-core-parent | maven | < 17.0 | 17.0 |
Vulnerability Intelligence
Miggo AI
Root Cause Analysis
The vulnerability stems from improper file location handling for JBOSS_LOCAL_USER challenges. Based on CWE-552 and the description of 'incorrect challenge location', the analysis focuses on Elytron components managing local authentication. The LocalUserRepository and JBossLocalUserServerAuthenticationMechanism classes are core to this functionality. The medium confidence reflects inference from vulnerability patterns rather than direct patch analysis. Functions handling challenge file creation/path resolution would be critical vectors, as the flaw allowed global rather than user-specific file access.