ZeroHour

CVE-2010-1428

KEV ransomwarelarge

HTTP Verb Bypass in Red Hat JBoss Web Console Allows Information Disclosure

CISA: Red Hat JBoss Information Disclosure Vulnerability

CVSS
EPSS
62%p99
Published
KEV added
AI analysis

The default block on unauthenticated access to the JBoss Application Server Web Console (/web-console) is incomplete: it only restricts the GET and POST HTTP verbs. A remote, unauthenticated attacker can therefore send requests using other HTTP verbs to bypass the access control and retrieve sensitive information exposed by the web console. Any deployment of affected Red Hat JBoss releases in which the web console is reachable, especially internet-exposed instances relying on the default block, is affected. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-05-25 with known ransomware use, indicating active exploitation, though no public proof-of-concept is known and CVSS scoring is still pending.

What to do: Apply updates per the vendor's instructions, as required by CISA's KEV listing. As interim mitigation, ensure /web-console enforces authentication for all HTTP methods, restrict or filter non-GET/POST verbs at a reverse proxy or firewall, or remove internet exposure of the web console. Review logs for non-GET/POST requests to /web-console, given known ransomware use.

Affected
Red Hat JBoss (Application Server Web Console)
Estimated exposure
large≈10,000–100,000 JBoss instances (tens of thousands historically observed exposed in internet-wide scans) — Historical internet-wide scan data has shown tens of thousands of exposed JBoss servers, and only deployments relying on the default web-console block are exploitable, putting the plausible affected set in the tens of thousands.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Unauthenticated access to the JBoss Application Server Web Console (/web-console) is blocked by default. However, it was found that this block was incomplete, and only blocked GET and POST HTTP verbs. A remote attacker could use this flaw to gain access to sensitive information.

CISA Known Exploited Vulnerability
Affected
Red Hat JBoss
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
Red Hat
Products
JBoss
Weakness
CWE-264

In the news

No ingested article mentions this CVE yet.