---
id: CVE-2024-1233
title: 'Eap: wildfly-elytron has a ssrf security issue'
summary: >-
  A flaw was found in` JwtValidator.resolvePublicKey` in JBoss EAP, where the
  validator checks jku and sends a HTTP request. During this process, no
  whitelisting or other filtering behavior is performed on the destination URL
  address, whic…
severity: high
cvss: 7.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'
cvssSource: cna
cwe:
  - CWE-918
vendor: Red Hat
product: wildfly
affected:
  - wildfly < 32.0.0.Final
  - org.wildfly.security/wildfly-elytron (all versions)
  - eap7-glassfish-el (all versions)
  - eap7-hibernate (all versions)
  - eap7-jackson-databind (all versions)
  - eap7-jboss-ejb-client (all versions)
  - eap7-netty (all versions)
  - eap7-undertow (all versions)
  - eap7-wildfly (all versions)
  - eap7-wildfly-elytron (all versions)
  - eap7-wildfly-http-client (all versions)
  - eap7-wildfly-naming-client (all versions)
  - eap7-wildfly-openssl (all versions)
  - eap7-wildfly-openssl-linux (all versions)
  - eap7-jackson-annotations (all versions)
  - eap7-jackson-core (all versions)
  - eap7-jackson-databind (all versions)
  - eap7-jackson-jaxrs-providers (all versions)
  - eap7-jackson-modules-base (all versions)
  - eap7-jackson-modules-java8 (all versions)
  - eap7-jboss-server-migration (all versions)
  - eap7-netty (all versions)
  - eap7-undertow (all versions)
  - eap7-wildfly (all versions)
  - eap7-wildfly-elytron (all versions)
  - eap7-apache-cxf (all versions)
  - eap7-hal-console (all versions)
  - eap7-infinispan (all versions)
  - eap7-jboss-ejb-client (all versions)
  - eap7-jboss-jsf-api_2.3_spec (all versions)
  - eap7-jboss-metadata (all versions)
  - eap7-jboss-modules (all versions)
  - eap7-jboss-server-migration (all versions)
  - eap7-undertow (all versions)
  - eap7-wildfly (all versions)
  - eap7-wildfly-discovery (all versions)
  - eap7-wildfly-elytron (all versions)
  - eap7-wildfly-http-client (all versions)
  - eap7-wildfly-transaction-client (all versions)
  - eap7-wss4j (all versions)
  - eap7-xml-security (all versions)
  - eap7-apache-cxf (all versions)
  - eap7-hal-console (all versions)
  - eap7-infinispan (all versions)
  - eap7-jboss-ejb-client (all versions)
  - eap7-jboss-jsf-api_2.3_spec (all versions)
  - eap7-jboss-metadata (all versions)
  - eap7-jboss-modules (all versions)
  - eap7-jboss-server-migration (all versions)
  - eap7-undertow (all versions)
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2024-04-09T19:46:50.360202Z'
published: '2024-04-09'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T03:01:05.073Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2024-1233'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2024:3559'
    label: 'RHSA-2024:3559'
  - url: 'https://access.redhat.com/errata/RHSA-2024:3560'
    label: 'RHSA-2024:3560'
  - url: 'https://access.redhat.com/errata/RHSA-2024:3561'
    label: 'RHSA-2024:3561'
  - url: 'https://access.redhat.com/errata/RHSA-2024:3563'
    label: 'RHSA-2024:3563'
  - url: 'https://access.redhat.com/errata/RHSA-2024:3580'
    label: 'RHSA-2024:3580'
  - url: 'https://access.redhat.com/errata/RHSA-2024:3581'
    label: 'RHSA-2024:3581'
  - url: 'https://access.redhat.com/errata/RHSA-2024:3583'
    label: 'RHSA-2024:3583'
  - url: 'https://access.redhat.com/errata/RHSA-2025:9582'
    label: 'RHSA-2025:9582'
  - url: 'https://access.redhat.com/errata/RHSA-2025:9583'
    label: 'RHSA-2025:9583'
  - url: 'https://access.redhat.com/security/cve/CVE-2024-1233'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2262849'
    label: RHBZ#2262849
  - url: 'https://github.com/advisories/GHSA-v4mm-q8fv-r2w5'
  - url: >-
      https://github.com/wildfly/wildfly/pull/17812/commits/0c02350bc0d84287bed46e7c32f90b36e50d3523
  - url: 'https://issues.redhat.com/browse/WFLY-19226'
tags:
  - cve.org
epss: 0.00778
epssPercentile: 0.54095
ingestedAt: '2026-10-01T03:36:04.808Z'
---

## Overview

A flaw was found in` JwtValidator.resolvePublicKey` in JBoss EAP, where the validator checks jku and sends a HTTP request. During this process, no whitelisting or other filtering behavior is performed on the destination URL address, which may result in a server-side request forgery (SSRF) vulnerability.

## Affected

- `wildfly < 32.0.0.Final`
- `org.wildfly.security/wildfly-elytron (all versions)`
- `eap7-glassfish-el (all versions)`
- `eap7-hibernate (all versions)`
- `eap7-jackson-databind (all versions)`
- `eap7-jboss-ejb-client (all versions)`
- `eap7-netty (all versions)`
- `eap7-undertow (all versions)`
- `eap7-wildfly (all versions)`
- `eap7-wildfly-elytron (all versions)`
- `eap7-wildfly-http-client (all versions)`
- `eap7-wildfly-naming-client (all versions)`
- `eap7-wildfly-openssl (all versions)`
- `eap7-wildfly-openssl-linux (all versions)`
- `eap7-jackson-annotations (all versions)`
- `eap7-jackson-core (all versions)`
- `eap7-jackson-databind (all versions)`
- `eap7-jackson-jaxrs-providers (all versions)`
- `eap7-jackson-modules-base (all versions)`
- `eap7-jackson-modules-java8 (all versions)`
- `eap7-jboss-server-migration (all versions)`
- `eap7-netty (all versions)`
- `eap7-undertow (all versions)`
- `eap7-wildfly (all versions)`
- `eap7-wildfly-elytron (all versions)`
- `eap7-apache-cxf (all versions)`
- `eap7-hal-console (all versions)`
- `eap7-infinispan (all versions)`
- `eap7-jboss-ejb-client (all versions)`
- `eap7-jboss-jsf-api_2.3_spec (all versions)`
- `eap7-jboss-metadata (all versions)`
- `eap7-jboss-modules (all versions)`
- `eap7-jboss-server-migration (all versions)`
- `eap7-undertow (all versions)`
- `eap7-wildfly (all versions)`
- `eap7-wildfly-discovery (all versions)`
- `eap7-wildfly-elytron (all versions)`
- `eap7-wildfly-http-client (all versions)`
- `eap7-wildfly-transaction-client (all versions)`
- `eap7-wss4j (all versions)`
- `eap7-xml-security (all versions)`
- `eap7-apache-cxf (all versions)`
- `eap7-hal-console (all versions)`
- `eap7-infinispan (all versions)`
- `eap7-jboss-ejb-client (all versions)`
- `eap7-jboss-jsf-api_2.3_spec (all versions)`
- `eap7-jboss-metadata (all versions)`
- `eap7-jboss-modules (all versions)`
- `eap7-jboss-server-migration (all versions)`
- `eap7-undertow (all versions)`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

### Workarounds

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
