4.4

CVE-2026-17614

Wildfly-core: path traversal on wildfly domain controller

A path traversal flaw was found in WildFly's domain mode
  implementation. The LocalFileRepository.getFile() and
  getConfigurationFile() methods in
  wildfly-core/deployment-repository do not validate that the
  resolved file path remains within the configured repository or
  configuration root directories. A remote attacker who has
  obtained the slave host controller secret or compromised a slave
  host controller can supply a crafted relative path containing
  directory traversal sequences (e.g., ../../etc/passwd) via the
  slave-DC wire protocol, causing the Domain Controller to resolve
  and serve arbitrary files readable by the DC process. This leads
  to unauthorized disclosure of sensitive information such as
  configuration files, keystores, and system credentials.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerRed Hat
Produkt Red Hat JBoss Enterprise Application Platform 7
Default Statusaffected
HerstellerRed Hat
Produkt Red Hat JBoss Enterprise Application Platform 7
Default Statusaffected
HerstellerRed Hat
Produkt Red Hat JBoss Enterprise Application Platform 7
Default Statusaffected
HerstellerRed Hat
Produkt Red Hat JBoss Enterprise Application Platform 7
Default Statusaffected
HerstellerRed Hat
Produkt Red Hat JBoss Enterprise Application Platform 7
Default Statusaffected
HerstellerRed Hat
Produkt Red Hat JBoss Enterprise Application Platform 7
Default Statusaffected
HerstellerRed Hat
Produkt Red Hat JBoss Enterprise Application Platform 8
Default Statusaffected
HerstellerRed Hat
Produkt Red Hat JBoss Enterprise Application Platform Expansion Pack
Default Statusaffected
HerstellerRed Hat
Produkt Red Hat Single Sign-On 7
Default Statusaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.85% 0.546
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
RedHat 4.4 0.7 3.6
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

https://access.redhat.com/security/cve/CVE-2026-17614
https://bugzilla.redhat.com/show_bug.cgi?id=2507631