---
id: CVE-2024-4029
title: A vulnerability was found in Wildfly’s management interface
summary: >-
  A vulnerability was found in Wildfly’s management interface. Due to the lack
  of limitation of sockets for the management interface, it may be possible to
  cause a denial of service hitting the nofile limit as there is no possibility
  to co…
severity: medium
cvss: 4.1
cvssVector: 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-770
vendor: Red Hat
product: wildfly
affected:
  - wildfly < 24.0.1.Final
  - org.wildfly.core/wildfly-domain-http-interface (all versions)
  - eap7-hal-console (all versions)
  - eap7-hibernate-validator (all versions)
  - eap7-insights-java-client (all versions)
  - eap7-ironjacamar (all versions)
  - eap7-jboss-cert-helper (all versions)
  - eap7-jboss-ejb-client (all versions)
  - eap7-jboss-server-migration (all versions)
  - eap7-jbossws-cxf (all versions)
  - eap7-jsoup (all versions)
  - eap7-undertow-jastow (all versions)
  - eap7-wildfly (all versions)
  - eap7-xalan-j2 (all versions)
  - eap7-hal-console (all versions)
  - eap7-hibernate-validator (all versions)
  - eap7-insights-java-client (all versions)
  - eap7-ironjacamar (all versions)
  - eap7-jboss-cert-helper (all versions)
  - eap7-jboss-ejb-client (all versions)
  - eap7-jboss-server-migration (all versions)
  - eap7-jbossws-cxf (all versions)
  - eap7-jsoup (all versions)
  - eap7-undertow-jastow (all versions)
  - eap7-wildfly (all versions)
  - eap7-xalan-j2 (all versions)
  - eap7-hal-console (all versions)
  - eap7-hibernate-validator (all versions)
  - eap7-insights-java-client (all versions)
  - eap7-ironjacamar (all versions)
  - eap7-jboss-cert-helper (all versions)
  - eap7-jboss-ejb-client (all versions)
  - eap7-jboss-server-migration (all versions)
  - eap7-jbossws-cxf (all versions)
  - eap7-jsoup (all versions)
  - eap7-undertow-jastow (all versions)
  - eap7-wildfly (all versions)
  - eap7-xalan-j2 (all versions)
  - wildfly-domain-http
  - eap8-activemq-artemis (all versions)
  - eap8-activemq-artemis-native (all versions)
  - eap8-aesh-extensions (all versions)
  - eap8-aesh-readline (all versions)
  - eap8-apache-commons-codec (all versions)
  - eap8-apache-commons-collections (all versions)
  - eap8-apache-commons-io (all versions)
  - eap8-apache-commons-lang (all versions)
  - eap8-apache-cxf (all versions)
  - eap8-artemis-native (all versions)
  - eap8-artemis-wildfly-integration (all versions)
published: '2024-05-02'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T04:17:34.033'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-4029'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2024:8075'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:8076'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:8077'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:8080'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:8823'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:8824'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:8826'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2024-4029'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2278615'
    label: secalert@redhat.com
  - url: 'https://github.com/advisories/GHSA-x7g6-rwhc-g7mj'
    label: secalert@redhat.com
  - url: 'https://github.com/wildfly/wildfly/pull/17914'
    label: secalert@redhat.com
  - url: 'https://github.com/wildfly/wildfly/pull/17935'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2024-4029'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2278615'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-4029.json
  - url: 'https://www.cve.org/CVERecord?id=CVE-2024-4029'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2024-4029'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2024-06-14T19:17:30.528404Z'
epss: 0.00277
epssPercentile: 0.18102
ingestedAt: '2026-06-26T16:43:13.385Z'
patched:
  - jboss_eap_7_4_for_rhel_7_server
  - jboss_eap_7_4_for_rhel 8
  - jboss_eap_8_0_for_rhel 8
  - jboss_eap_7_4_for_rhel 9
  - jboss_eap_8_0_for_rhel 9
  - jboss_enterprise_application_platform 8
  - jboss_enterprise_application_platform
---

## Overview

A vulnerability was found in Wildfly’s management interface. Due to the lack of limitation of sockets for the management interface, it may be possible to cause a denial of service hitting the nofile limit as there is no possibility to configure or set a maximum number of connections.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **RHSA-2024:8075** · Red Hat · fixed in: Red Hat JBoss EAP 7.4 for RHEL 7 Server · released 2024-10-14 · [advisory](https://access.redhat.com/errata/RHSA-2024:8075)
- **RHSA-2024:8076** · Red Hat · fixed in: Red Hat JBoss EAP 7.4 for RHEL 8 · released 2024-10-14 · [advisory](https://access.redhat.com/errata/RHSA-2024:8076)
- **RHSA-2024:8823** · Red Hat · fixed in: Red Hat JBoss EAP 8.0 for RHEL 8 · released 2024-11-04 · [advisory](https://access.redhat.com/errata/RHSA-2024:8823)
- **RHSA-2024:8077** · Red Hat · fixed in: Red Hat JBoss EAP 7.4 for RHEL 9 · released 2024-10-14 · [advisory](https://access.redhat.com/errata/RHSA-2024:8077)
- **RHSA-2024:8824** · Red Hat · fixed in: Red Hat JBoss EAP 8.0 for RHEL 9 · released 2024-11-04 · [advisory](https://access.redhat.com/errata/RHSA-2024:8824)
- **RHSA-2024:8826** · Red Hat · fixed in: Red Hat JBoss Enterprise Application Platform 8 · released 2024-11-04 · [advisory](https://access.redhat.com/errata/RHSA-2024:8826)
- **RHSA-2024:8080** · Red Hat · fixed in: Red Hat JBoss Enterprise Application Platform · released 2024-10-14 · [advisory](https://access.redhat.com/errata/RHSA-2024:8080)
- **Red Hat VEX** · Low · affected: Red Hat Fuse 7, Red Hat JBoss Data Grid 7, Red Hat Process Automation 7, Red Hat Single Sign-On 7 · no fix planned: Red Hat Fuse 7, Red Hat JBoss Data Grid 7, Red Hat Process Automation 7, Red Hat Single Sign-On 7 · updated 2026-09-24 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-4029.json)
