ZeroHour

CVE-2021-3642

CVSS 3.1
5.3 medium
EPSS
<1%p56
Published
()
Modified
Description

A flaw was found in Wildfly Elytron in versions prior to 1.10.14.Final, prior to 1.15.5.Final and prior to 1.16.1.Final where ScramServer may be susceptible to Timing Attack if enabled. The highest threat of this vulnerability is confidentiality.

Vendors
redhatquarkus
Products
wildfly elytron, build of quarkus, codeready studio, data grid, descision manager, integration camel k, integration camel quarkus, jboss enterprise application platform, jboss enterprise application platform expansion pack, jboss fuse, openshift application runtimes, process automation
Weakness
CWE-203
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.