VulnerabilityModified
CVE-2021-3642
The highest threat of this vulnerability is confidentiality.
MEDIUM 5.3EPSS 0.85%
Does this matter?
Lower severity and a low EPSS score (0.85%). Track it; it rarely justifies an emergency change on its own.
Description
A flaw was found in Wildfly Elytron in versions prior to 1.10.14.Final, prior to 1.15.5.Final and prior to 1.16.1.Final where ScramServer may be susceptible to Timing Attack if enabled. The highest threat of this vulnerability is confidentiality.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.85% probability · 56th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-203
- Affected
- redhat/wildfly elytron · redhat/build of quarkus · redhat/codeready studio · redhat/data grid · redhat/descision manager · redhat/integration camel k · redhat/integration camel quarkus · redhat/jboss enterprise application platform · redhat/jboss enterprise application platform expansion pack · redhat/jboss fuse · redhat/openshift application runtimes · redhat/process automation · quarkus/quarkus
- Source
- secalert@redhat.com
References
- https://bugzilla.redhat.com/show_bug.cgi?id=1981407Issue Tracking, Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1981407Issue Tracking, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.