ZeroHour

CVE-2016-8627

CVSS 3.0
6.5 medium
EPSS
3%p85
Published
()
Modified
Description

admin-cli before versions 3.0.0.alpha25, 2.2.1.cr2 is vulnerable to an EAP feature to download server log files that allows logs to be available via GET requests making them vulnerable to cross-origin attacks. An attacker could trigger the user's browser to request the log files consuming enough resources that normal server functioning could be impaired.

Vendors
redhat
Products
jboss enterprise application platform, keycloak
Weakness
CWE-400
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.