---
id: CVE-2023-4061
title: A flaw was found in wildfly-core
summary: >-
  A flaw was found in wildfly-core. A management user could use the
  resolve-expression in the HAL Interface to read possible sensitive information
  from the Wildfly system. This issue could allow a malicious user to access the
  system and ob…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'
cwe:
  - CWE-200
vendor: redhat
product: jboss_enterprise_application_platform
affected:
  - jboss_enterprise_application_platform
  - wildfly_core < 15.0.30
  - jboss_enterprise_application_platform = 7.4
patched:
  - wildfly_core 15.0.30
published: '2023-11-08'
updated: '2026-09-23'
sourceUpdated: '2026-09-23T14:17:05.097'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2023-4061'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2023:5484'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2023:5485'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2023:5486'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2023:5488'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2023-4061'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2228608'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2023:5484'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2023:5485'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2023:5486'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2023:5488'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/security/cve/CVE-2023-4061'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2228608'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-4061.json
  - url: 'https://www.cve.org/CVERecord?id=CVE-2023-4061'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2023-4061'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2024-04-26T20:01:33.866369Z'
epss: 0.00834
epssPercentile: 0.5619
ingestedAt: '2026-09-23T14:25:29.761Z'
---

## Overview

A flaw was found in wildfly-core. A management user could use the resolve-expression in the HAL Interface to read possible sensitive information from the Wildfly system. This issue could allow a malicious user to access the system and obtain possible sensitive information from the system.

## Affected

- `jboss_enterprise_application_platform`
- `wildfly_core < 15.0.30`
- `jboss_enterprise_application_platform = 7.4`

## Remediation

Upgrade past the affected range:

- `wildfly_core 15.0.30`

## Vendor advisories

- **RHSA-2023:5484** · Red Hat · fixed in: Red Hat JBoss EAP 7.4 for RHEL 7 Server · released 2023-10-05 · [advisory](https://access.redhat.com/errata/RHSA-2023:5484)
- **RHSA-2023:5485** · Red Hat · fixed in: Red Hat JBoss EAP 7.4 for RHEL 8 · released 2023-10-06 · [advisory](https://access.redhat.com/errata/RHSA-2023:5485)
- **RHSA-2023:5486** · Red Hat · fixed in: Red Hat JBoss EAP 7.4 for RHEL 9 · released 2023-10-06 · [advisory](https://access.redhat.com/errata/RHSA-2023:5486)
- **RHSA-2023:5488** · Red Hat · fixed in: Red Hat JBoss Enterprise Application Platform · released 2023-10-05 · [advisory](https://access.redhat.com/errata/RHSA-2023:5488)
