SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-3642

The highest threat of this vulnerability is confidentiality.

MEDIUM 5.3EPSS 0.85%

Does this matter?

Lower severity and a low EPSS score (0.85%). Track it; it rarely justifies an emergency change on its own.

Description

A flaw was found in Wildfly Elytron in versions prior to 1.10.14.Final, prior to 1.15.5.Final and prior to 1.16.1.Final where ScramServer may be susceptible to Timing Attack if enabled. The highest threat of this vulnerability is confidentiality.

CVSS 3.1
5.3 MEDIUMCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS
0.85% probability · 56th percentile
CISA KEV
Not listed
Weakness
CWE-203
Affected
redhat/wildfly elytron · redhat/build of quarkus · redhat/codeready studio · redhat/data grid · redhat/descision manager · redhat/integration camel k · redhat/integration camel quarkus · redhat/jboss enterprise application platform · redhat/jboss enterprise application platform expansion pack · redhat/jboss fuse · redhat/openshift application runtimes · redhat/process automation · quarkus/quarkus
Source
secalert@redhat.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.