A flaw was found in Wildfly in versions before 23.0.2.Final while creating a new role in domain mode via the admin console, it is possible to add a payload in the name field, leading to XSS. This affects Confidentiality and Integrity.
{
"unresolved_ranges": [
{
"source": "CPE_FIELD",
"vendor_product": "redhat:data_grid",
"cpes": [
"cpe:2.3:a:redhat:data_grid:8.0:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"last_affected": "8.0"
}
]
},
{
"source": "CPE_FIELD",
"vendor_product": "redhat:descision_manager",
"cpes": [
"cpe:2.3:a:redhat:descision_manager:7.0:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"last_affected": "7.0"
}
]
},
{
"source": "CPE_FIELD",
"cpes": [
"cpe:2.3:a:redhat:jboss_a-mq:7:*:*:*:*:*:*:*"
],
"vendor_product": "redhat:jboss_a-mq",
"extracted_events": [
{
"last_affected": "7"
}
]
},
{
"source": "CPE_FIELD",
"vendor_product": "redhat:jboss_enterprise_application_platform",
"cpes": [
"cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.0:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"last_affected": "7.0"
}
]
}
]
}