{"id":"CVE-2023-4061","title":"A flaw was found in wildfly-core","summary":"A flaw was found in wildfly-core. A management user could use the resolve-expression in the HAL Interface to read possible sensitive information from the Wildfly system. This issue could allow a malicious user to access the system and ob…","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","cwe":["CWE-200"],"vendor":"redhat","product":"jboss_enterprise_application_platform","affected":["jboss_enterprise_application_platform","wildfly_core < 15.0.30","jboss_enterprise_application_platform = 7.4"],"patched":["wildfly_core 15.0.30"],"published":"2023-11-08","updated":"2026-09-23","sourceUpdated":"2026-09-23T14:17:05.097","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2023-4061","references":[{"url":"https://access.redhat.com/errata/RHSA-2023:5484","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2023:5485","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2023:5486","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2023:5488","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/security/cve/CVE-2023-4061","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2228608","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2023:5484","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2023:5485","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2023:5486","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2023:5488","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/security/cve/CVE-2023-4061","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2228608","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2024-04-26T20:01:33.866369Z"},"epss":0.00834,"epssPercentile":0.56153,"ingestedAt":"2026-09-23T14:25:29.761Z","slug":"CVE-2023-4061","body":"## Overview\n\nA flaw was found in wildfly-core. A management user could use the resolve-expression in the HAL Interface to read possible sensitive information from the Wildfly system. This issue could allow a malicious user to access the system and obtain possible sensitive information from the system.\n\n## Affected\n\n- `jboss_enterprise_application_platform`\n- `wildfly_core < 15.0.30`\n- `jboss_enterprise_application_platform = 7.4`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `wildfly_core 15.0.30`","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}