CVE-2024-1233: Red Hat JBoss Enterprise Application Platform
High severity, CVSS 7.3. EPSS: 0.8% chance of exploitation in the next 30 days.
A flaw was found in` JwtValidator.resolvePublicKey` in JBoss EAP, where the validator checks jku and sends a HTTP request. During this process, no whitelisting or other filtering behavior is performed on the destination URL address, which may result in a server-side request forgery (SSRF) vulnerability.
Affected products
- Red Hat Red Hat JBoss Enterprise Application Platform: before 1.15.23.Final-redhat-00001 (fixed in 1.15.23.Final-redhat-00001)
- Red Hat Red Hat JBoss Enterprise Application Platform 7.1 Eus For Rhel 7: before 0:3.0.1-4.b08_redhat_00005.1.ep7.el7 (fixed in 0:3.0.1-4.b08_redhat_00005.1.ep7.el7); before 0:5.1.17-3.Final_redhat_00004.1.ep7.el7 (fixed in 0:5.1.17-3.Final_redhat_00004.1.ep7.el7); before 0:2.8.11.6-3.SP1_redhat_00003.1.ep7.el7 (fixed in 0:2.8.11.6-3.SP1_redhat_00003.1.ep7.el7); before 0:4.0.12-1.Final_redhat_00002.1.ep7.el7 (fixed in 0:4.0.12-1.Final_redhat_00002.1.ep7.el7); before 0:4.1.63-2.Final_redhat_00003.1.ep7.el7 (fixed in 0:4.1.63-2.Final_redhat_00003.1.ep7.el7); before 0:1.4.18-16.SP14_redhat_00001.1.ep7.el7 (fixed in 0:1.4.18-16.SP14_redhat_00001.1.ep7.el7); …
- Red Hat Red Hat JBoss Enterprise Application Platform 7.3 Eus For Rhel 7: before 0:2.10.4-3.redhat_00006.1.el7eap (fixed in 0:2.10.4-3.redhat_00006.1.el7eap); before 0:2.10.4-5.redhat_00006.1.el7eap (fixed in 0:2.10.4-5.redhat_00006.1.el7eap); before 0:2.10.4-2.redhat_00006.1.el7eap (fixed in 0:2.10.4-2.redhat_00006.1.el7eap); before 0:1.7.2-16.Final_redhat_00017.1.el7eap (fixed in 0:1.7.2-16.Final_redhat_00017.1.el7eap); before 0:4.1.63-5.Final_redhat_00003.1.el7eap (fixed in 0:4.1.63-5.Final_redhat_00003.1.el7eap); before 0:2.0.41-4.SP5_redhat_00001.1.el7eap (fixed in 0:2.0.41-4.SP5_redhat_00001.1.el7eap); …
- Red Hat Red Hat JBoss Enterprise Application Platform 7.4 For Rhel 8: before 0:3.5.8-1.redhat_00001.1.el8eap (fixed in 0:3.5.8-1.redhat_00001.1.el8eap); before 0:3.3.22-1.Final_redhat_00001.1.el8eap (fixed in 0:3.3.22-1.Final_redhat_00001.1.el8eap); before 0:11.0.19-2.Final_redhat_00001.1.el8eap (fixed in 0:11.0.19-2.Final_redhat_00001.1.el8eap); before 0:4.0.54-3.Final_redhat_00001.1.el8eap (fixed in 0:4.0.54-3.Final_redhat_00001.1.el8eap); before 0:3.0.0-8.SP08_redhat_00001.1.el8eap (fixed in 0:3.0.0-8.SP08_redhat_00001.1.el8eap); before 0:13.5.0-1.Final_redhat_00001.1.el8eap (fixed in 0:13.5.0-1.Final_redhat_00001.1.el8eap); …
- Red Hat Red Hat JBoss Enterprise Application Platform 7.4 For Rhel 9: before 0:3.5.8-1.redhat_00001.1.el9eap (fixed in 0:3.5.8-1.redhat_00001.1.el9eap); before 0:3.3.22-1.Final_redhat_00001.1.el9eap (fixed in 0:3.3.22-1.Final_redhat_00001.1.el9eap); before 0:11.0.19-2.Final_redhat_00001.1.el9eap (fixed in 0:11.0.19-2.Final_redhat_00001.1.el9eap); before 0:4.0.54-3.Final_redhat_00001.1.el9eap (fixed in 0:4.0.54-3.Final_redhat_00001.1.el9eap); before 0:3.0.0-8.SP08_redhat_00001.1.el9eap (fixed in 0:3.0.0-8.SP08_redhat_00001.1.el9eap); before 0:13.5.0-1.Final_redhat_00001.1.el9eap (fixed in 0:13.5.0-1.Final_redhat_00001.1.el9eap); …
- Red Hat Red Hat JBoss Enterprise Application Platform 7.4 On Rhel 7: before 0:1.15.23-2.Final_redhat_00001.1.el7eap (fixed in 0:1.15.23-2.Final_redhat_00001.1.el7eap)
- Red Hat Red Hat JBoss Enterprise Application Platform 8
- Red Hat Red Hat JBoss Enterprise Application Platform 8.0 For Rhel 8: before 0:4.0.1-1.Final_redhat_00001.1.el8eap (fixed in 0:4.0.1-1.Final_redhat_00001.1.el8eap); before 0:2.2.4-2.SP01_redhat_00001.1.el8eap (fixed in 0:2.2.4-2.SP01_redhat_00001.1.el8eap)
- Red Hat Red Hat JBoss Enterprise Application Platform 8.0 For Rhel 9: before 0:4.0.1-1.Final_redhat_00001.1.el9eap (fixed in 0:4.0.1-1.Final_redhat_00001.1.el9eap); before 0:2.2.4-2.SP01_redhat_00001.1.el9eap (fixed in 0:2.2.4-2.SP01_redhat_00001.1.el9eap)
- Red Hat Red Hat JBoss Enterprise Application Platform Expansion Pack
Published 2024-04-09. Last modified 2026-06-17.