CVE-2024-1233High· 7.3▾ TwilightA flaw was found in` JwtValidator.resolvePublicKey` in JBoss EAP, where the validator checks jku and sends a HTTP request. During this process, no whitelisting or other filtering behavior is performed on the destination URL address, whic…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 40.2 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake. The CVSS score shown above comes from the assigning CNA record, not NVD.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CVEORG
Last analysed / modified upstream
0.8%
A flaw was found in JwtValidator.resolvePublicKey in JBoss EAP, where the validator checks jku and sends a HTTP request. During this process, no whitelisting or other filtering behavior is performed on the destination URL address, which may result in a server-side request forgery (SSRF) vulnerability.
wildfly < 32.0.0.Finalorg.wildfly.security/wildfly-elytron (all versions)eap7-glassfish-el (all versions)eap7-hibernate (all versions)eap7-jackson-databind (all versions)eap7-jboss-ejb-client (all versions)eap7-netty (all versions)eap7-undertow (all versions)eap7-wildfly (all versions)eap7-wildfly-elytron (all versions)eap7-wildfly-http-client (all versions)eap7-wildfly-naming-client (all versions)eap7-wildfly-openssl (all versions)eap7-wildfly-openssl-linux (all versions)eap7-jackson-annotations (all versions)eap7-jackson-core (all versions)eap7-jackson-databind (all versions)eap7-jackson-jaxrs-providers (all versions)eap7-jackson-modules-base (all versions)eap7-jackson-modules-java8 (all versions)eap7-jboss-server-migration (all versions)eap7-netty (all versions)eap7-undertow (all versions)eap7-wildfly (all versions)eap7-wildfly-elytron (all versions)eap7-apache-cxf (all versions)eap7-hal-console (all versions)eap7-infinispan (all versions)eap7-jboss-ejb-client (all versions)eap7-jboss-jsf-api_2.3_spec (all versions)eap7-jboss-metadata (all versions)eap7-jboss-modules (all versions)eap7-jboss-server-migration (all versions)eap7-undertow (all versions)eap7-wildfly (all versions)eap7-wildfly-discovery (all versions)eap7-wildfly-elytron (all versions)eap7-wildfly-http-client (all versions)eap7-wildfly-transaction-client (all versions)eap7-wss4j (all versions)eap7-xml-security (all versions)eap7-apache-cxf (all versions)eap7-hal-console (all versions)eap7-infinispan (all versions)eap7-jboss-ejb-client (all versions)eap7-jboss-jsf-api_2.3_spec (all versions)eap7-jboss-metadata (all versions)eap7-jboss-modules (all versions)eap7-jboss-server-migration (all versions)eap7-undertow (all versions)Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-51773High· 8.1An issue in the VMware datastore driver of OpenStack glance_store
CVE-2026-84721Medium· 6.4A server-side request forgery flaw was found in the Ansible Automation Platform automation-controller email notification backend
CVE-2025-68616High· 7.5WeasyPrint helps web developers to create PDF documents
CVE-2026-0532High· 8.6External Control of File Name or Path (CWE-73) combined with Server-Side Request Forgery (CWE-918) can allow an attacker to cause arbitrary file disclosure through a specially crafted credentials JSON payload in the Google Gemini connect…
CVE-2024-4029Medium· 4.1A vulnerability was found in Wildfly’s management interface
CVE-2026-103641Medium· 5.5A flaw was found in GEGL