In` JwtValidator.resolvePublicKey`, the Validator checks jku and sends an HTTP request. During this process, no whitelisting or other filtering behavior was performed on the destination URL address. Caused SSRF vulnerability.
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7 Via RHSA-2024:3559 https://access.redhat.com/errata/RHSA-2024:3559
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 Via RHSA-2024:3561 https://access.redhat.com/errata/RHSA-2024:3561
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 Via RHSA-2024:3560 https://access.redhat.com/errata/RHSA-2024:3560
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform Via RHSA-2024:3563 https://access.redhat.com/errata/RHSA-2024:3563
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform Via RHSA-2024:3583 https://access.redhat.com/errata/RHSA-2024:3583
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 Via RHSA-2024:3581 https://access.redhat.com/errata/RHSA-2024:3581
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 Via RHSA-2024:3580 https://access.redhat.com/errata/RHSA-2024:3580
Upstream Advisory: https://github.com/advisories/GHSA-v4mm-q8fv-r2w5
Upstream Bug: https://issues.redhat.com/browse/WFLY-19226 Commit: https://github.com/wildfly/wildfly/pull/17812/commits/0c02350bc0d84287bed46e7c32f90b36e50d3523