CVE-2010-1428
KEV ransomwarelargeHTTP Verb Bypass in Red Hat JBoss Web Console Allows Information Disclosure
CISA: Red Hat JBoss Information Disclosure Vulnerability
The default block on unauthenticated access to the JBoss Application Server Web Console (/web-console) is incomplete: it only restricts the GET and POST HTTP verbs. A remote, unauthenticated attacker can therefore send requests using other HTTP verbs to bypass the access control and retrieve sensitive information exposed by the web console. Any deployment of affected Red Hat JBoss releases in which the web console is reachable, especially internet-exposed instances relying on the default block, is affected. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-05-25 with known ransomware use, indicating active exploitation, though no public proof-of-concept is known and CVSS scoring is still pending.
What to do: Apply updates per the vendor's instructions, as required by CISA's KEV listing. As interim mitigation, ensure /web-console enforces authentication for all HTTP methods, restrict or filter non-GET/POST verbs at a reverse proxy or firewall, or remove internet exposure of the web console. Review logs for non-GET/POST requests to /web-console, given known ransomware use.
| Red Hat JBoss (Application Server Web Console) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Unauthenticated access to the JBoss Application Server Web Console (/web-console) is blocked by default. However, it was found that this block was incomplete, and only blocked GET and POST HTTP verbs. A remote attacker could use this flaw to gain access to sensitive information.
- Affected
- Red Hat JBoss
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Known
- Vendors
- Red Hat
- Products
- JBoss
- Weakness
- CWE-264
In the news0 stories
No ingested article mentions this CVE yet.