支持本站 — 捐款将帮助我们持续运营

目标: 1000 元,已筹: 1000

100.0%
获取后续新漏洞提醒登录后订阅
一、 漏洞 CVE-2024-1233 基础信息
漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
Eap: wildfly-elytron has a ssrf security issue
来源: 美国国家漏洞数据库 NVD
Vulnerability Description
A flaw was found in` JwtValidator.resolvePublicKey` in JBoss EAP, where the validator checks jku and sends a HTTP request. During this process, no whitelisting or other filtering behavior is performed on the destination URL address, which may result in a server-side request forgery (SSRF) vulnerability.
来源: 美国国家漏洞数据库 NVD
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
来源: 美国国家漏洞数据库 NVD
Vulnerability Type
服务端请求伪造(SSRF)
来源: 美国国家漏洞数据库 NVD
Vulnerability Title
Red Hat JBoss Enterprise Application Platform 安全漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
Red Hat JBoss Enterprise Application Platform(EAP)是美国红帽(Red Hat)公司的一套开源的、基于J2EE的中间件平台。该平台主要用于构建、部署和托管Java应用程序与服务。 Red Hat JBoss Enterprise Application Platform 存在安全漏洞,该漏洞源于JwtValidator.resolvePublicKey存在致服务器请求伪造(SSRF)漏洞。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD
受影响产品
厂商产品影响版本CPE订阅
Red HatRed Hat JBoss Enterprise Application Platform 1.15.23.Final-redhat-00001 ~ * cpe:/a:redhat:jboss_enterprise_application_platform:7.4
Red HatRed Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 0:3.0.1-4.b08_redhat_00005.1.ep7.el7 ~ * cpe:/a:redhat:jboss_enterprise_application_platform_eus:7.1::el7
Red HatRed Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 0:5.1.17-3.Final_redhat_00004.1.ep7.el7 ~ * cpe:/a:redhat:jboss_enterprise_application_platform_eus:7.1::el7
Red HatRed Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 0:2.8.11.6-3.SP1_redhat_00003.1.ep7.el7 ~ * cpe:/a:redhat:jboss_enterprise_application_platform_eus:7.1::el7
Red HatRed Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 0:4.0.12-1.Final_redhat_00002.1.ep7.el7 ~ * cpe:/a:redhat:jboss_enterprise_application_platform_eus:7.1::el7
Red HatRed Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 0:4.1.63-2.Final_redhat_00003.1.ep7.el7 ~ * cpe:/a:redhat:jboss_enterprise_application_platform_eus:7.1::el7
Red HatRed Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 0:1.4.18-16.SP14_redhat_00001.1.ep7.el7 ~ * cpe:/a:redhat:jboss_enterprise_application_platform_eus:7.1::el7
Red HatRed Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 0:7.1.11-4.GA_redhat_00002.1.ep7.el7 ~ * cpe:/a:redhat:jboss_enterprise_application_platform_eus:7.1::el7
Red HatRed Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 0:1.1.14-1.Final_redhat_00001.1.ep7.el7 ~ * cpe:/a:redhat:jboss_enterprise_application_platform_eus:7.1::el7
Red HatRed Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 0:1.0.21-1.Final_redhat_00001.1.ep7.el7 ~ * cpe:/a:redhat:jboss_enterprise_application_platform_eus:7.1::el7
Red HatRed Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 0:1.0.13-1.Final_redhat_00001.1.ep7.el7 ~ * cpe:/a:redhat:jboss_enterprise_application_platform_eus:7.1::el7
Red HatRed Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 0:1.0.12-1.Final_redhat_00001.1.ep7.el7 ~ * cpe:/a:redhat:jboss_enterprise_application_platform_eus:7.1::el7
Red HatRed Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 0:1.0.12-6.Final_redhat_00001.1.ep7.el7 ~ * cpe:/a:redhat:jboss_enterprise_application_platform_eus:7.1::el7
Red HatRed Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 0:2.10.4-3.redhat_00006.1.el7eap ~ * cpe:/a:redhat:jboss_enterprise_application_platform_eus:7.3::el7
Red HatRed Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 0:2.10.4-3.redhat_00006.1.el7eap ~ * cpe:/a:redhat:jboss_enterprise_application_platform_eus:7.3::el7
Red HatRed Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 0:2.10.4-5.redhat_00006.1.el7eap ~ * cpe:/a:redhat:jboss_enterprise_application_platform_eus:7.3::el7
Red HatRed Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 0:2.10.4-3.redhat_00006.1.el7eap ~ * cpe:/a:redhat:jboss_enterprise_application_platform_eus:7.3::el7
Red HatRed Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 0:2.10.4-5.redhat_00006.1.el7eap ~ * cpe:/a:redhat:jboss_enterprise_application_platform_eus:7.3::el7
Red HatRed Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 0:2.10.4-2.redhat_00006.1.el7eap ~ * cpe:/a:redhat:jboss_enterprise_application_platform_eus:7.3::el7
Red HatRed Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 0:1.7.2-16.Final_redhat_00017.1.el7eap ~ * cpe:/a:redhat:jboss_enterprise_application_platform_eus:7.3::el7
Red HatRed Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 0:4.1.63-5.Final_redhat_00003.1.el7eap ~ * cpe:/a:redhat:jboss_enterprise_application_platform_eus:7.3::el7
Red HatRed Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 0:2.0.41-4.SP5_redhat_00001.1.el7eap ~ * cpe:/a:redhat:jboss_enterprise_application_platform_eus:7.3::el7
Red HatRed Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 0:7.3.14-3.GA_redhat_00002.1.el7eap ~ * cpe:/a:redhat:jboss_enterprise_application_platform_eus:7.3::el7
Red HatRed Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 0:1.10.17-1.Final_redhat_00001.1.el7eap ~ * cpe:/a:redhat:jboss_enterprise_application_platform_eus:7.3::el7
Red HatRed Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 0:3.5.8-1.redhat_00001.1.el8eap ~ * cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el8
Red HatRed Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 0:3.3.22-1.Final_redhat_00001.1.el8eap ~ * cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el8
Red HatRed Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 0:11.0.19-2.Final_redhat_00001.1.el8eap ~ * cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el8
Red HatRed Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 0:4.0.54-3.Final_redhat_00001.1.el8eap ~ * cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el8
Red HatRed Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 0:3.0.0-8.SP08_redhat_00001.1.el8eap ~ * cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el8
Red HatRed Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 0:13.5.0-1.Final_redhat_00001.1.el8eap ~ * cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el8
Red HatRed Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 0:1.12.3-3.Final_redhat_00001.1.el8eap ~ * cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el8
Red HatRed Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 0:1.10.0-36.Final_redhat_00035.1.el8eap ~ * cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el8
Red HatRed Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 0:2.2.32-1.SP1_redhat_00001.1.el8eap ~ * cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el8
Red HatRed Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 0:7.4.17-2.GA_redhat_00002.1.el8eap ~ * cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el8
Red HatRed Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 0:1.2.4-1.Final_redhat_00001.1.el8eap ~ * cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el8
Red HatRed Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 0:1.15.23-2.Final_redhat_00001.1.el8eap ~ * cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el8
Red HatRed Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 0:1.1.17-1.Final_redhat_00002.1.el8eap ~ * cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el8
Red HatRed Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 0:1.1.19-1.Final_redhat_00001.1.el8eap ~ * cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el8
Red HatRed Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 0:2.4.3-1.redhat_00001.1.el8eap ~ * cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el8
Red HatRed Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 0:2.3.4-1.redhat_00002.1.el8eap ~ * cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el8
Red HatRed Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 0:3.5.8-1.redhat_00001.1.el9eap ~ * cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el9
Red HatRed Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 0:3.3.22-1.Final_redhat_00001.1.el9eap ~ * cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el9
Red HatRed Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 0:11.0.19-2.Final_redhat_00001.1.el9eap ~ * cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el9
Red HatRed Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 0:4.0.54-3.Final_redhat_00001.1.el9eap ~ * cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el9
Red HatRed Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 0:3.0.0-8.SP08_redhat_00001.1.el9eap ~ * cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el9
Red HatRed Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 0:13.5.0-1.Final_redhat_00001.1.el9eap ~ * cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el9
Red HatRed Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 0:1.12.3-3.Final_redhat_00001.1.el9eap ~ * cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el9
Red HatRed Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 0:1.10.0-36.Final_redhat_00035.1.el9eap ~ * cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el9
Red HatRed Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 0:2.2.32-1.SP1_redhat_00001.1.el9eap ~ * cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el9
Red HatRed Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 0:7.4.17-2.GA_redhat_00002.1.el9eap ~ * cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el9
Red HatRed Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 0:1.2.4-1.Final_redhat_00001.1.el9eap ~ * cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el9
Red HatRed Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 0:1.15.23-2.Final_redhat_00001.1.el9eap ~ * cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el9
Red HatRed Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 0:1.1.17-1.Final_redhat_00002.1.el9eap ~ * cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el9
Red HatRed Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 0:1.1.19-1.Final_redhat_00001.1.el9eap ~ * cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el9
Red HatRed Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 0:2.4.3-1.redhat_00001.1.el9eap ~ * cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el9
Red HatRed Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 0:2.3.4-1.redhat_00002.1.el9eap ~ * cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el9
Red HatRed Hat JBoss Enterprise Application Platform 7.4 on RHEL 7 0:1.15.23-2.Final_redhat_00001.1.el7eap ~ * cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el7
Red HatRed Hat JBoss Enterprise Application Platform 8-cpe:/a:redhat:jboss_enterprise_application_platform:8.0
Red HatRed Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 0:4.0.1-1.Final_redhat_00001.1.el8eap ~ * cpe:/a:redhat:jboss_enterprise_application_platform:8.0::el8
Red HatRed Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 0:2.2.4-2.SP01_redhat_00001.1.el8eap ~ * cpe:/a:redhat:jboss_enterprise_application_platform:8.0::el8
Red HatRed Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 0:4.0.1-1.Final_redhat_00001.1.el9eap ~ * cpe:/a:redhat:jboss_enterprise_application_platform:8.0::el9
Red HatRed Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 0:2.2.4-2.SP01_redhat_00001.1.el9eap ~ * cpe:/a:redhat:jboss_enterprise_application_platform:8.0::el9
Red HatRed Hat JBoss Enterprise Application Platform Expansion Pack-cpe:/a:redhat:jbosseapxp
二、漏洞 CVE-2024-1233 的公开POC
#POC 描述源链接神龙链接
AI 生成 POC高级

未找到公开 POC。

登录以生成 AI POC
三、漏洞 CVE-2024-1233 的情报信息
Please 登录 to view more intelligence information
四、漏洞 CVE-2024-1233 的评论

暂无评论


发表评论