eap7-jboss-ejb-client vulnerabilities
CVEs whose affected-version data names the eap7-jboss-ejb-client package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2024-4029Medium· 4.1A vulnerability was found in Wildfly’s management interface
A vulnerability was found in Wildfly’s management interface. Due to the lack of limitation of sockets for the management interface, it may be possible to cause a denial of service hitting the nofile limit as there is no possibility to co…
▾ SunlitRed Hat · wildflyEPSS 0.28%via NVD
CVE-2024-1233High· 7.3Eap: wildfly-elytron has a ssrf security issue
A flaw was found in` JwtValidator.resolvePublicKey` in JBoss EAP, where the validator checks jku and sends a HTTP request. During this process, no whitelisting or other filtering behavior is performed on the destination URL address, whic…
▾ TwilightRed Hat · wildflyEPSS 0.78%via CVEORG