CVE-2023-4061: Red Hat JBoss Enterprise Application Platform

Medium severity, CVSS 6.5. EPSS: 1% chance of exploitation in the next 30 days.

A flaw was found in wildfly-core. A management user could use the resolve-expression in the HAL Interface to read possible sensitive information from the Wildfly system. This issue could allow a malicious user to access the system and obtain possible sensitive information from the system.

Affected products

  • Red Hat JBoss Enterprise Application Platform: affected versions not specified; version 7.4 only
  • Red Hat Wildfly Core: before 15.0.30 (fixed in 15.0.30)

Published 2023-11-08. Last modified 2026-09-23.