VDB
Sign up
HIGH7.3

GHSA-v4mm-q8fv-r2w5

WildFly Elytron: SSRF security issue

Details

A flaw was found in` JwtValidator.resolvePublicKey` in JBoss EAP, where the validator checks jku and sends a HTTP request. During this process, no whitelisting or other filtering behavior is performed on the destination URL address, which may result in a server-side request forgery (SSRF) vulnerability.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/org.wildfly.security:wildfly-elytron-realm-token
Introduced in: 0

No fixed version published yet for org.wildfly.security:wildfly-elytron-realm-token (maven). Pin to a known-safe version or switch to an alternative.

References