{"id":"CVE-2021-3717","aliases":["GHSA-p9xf-3rm3-qh2h"],"url":"https://o3.security/vulnerability/CVE-2021-3717","summary":"Wildfly-Core user account mismanagement","details":"A flaw was found in Wildfly. An incorrect JBOSS_LOCAL_USER challenge location when using the elytron configuration may lead to JBOSS_LOCAL_USER access to all users on the machine. The highest threat from this vulnerability is to confidentiality, integrity, and availability. This flaw affects wildfly-core versions prior to 17.0.","published":"2022-05-24T19:15:09.143Z","modified":"2026-07-08T05:57:13.619089023Z","cvss":{"score":7.8,"severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.wildfly.core:wildfly-core-parent","fixedVersion":"17.0"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20220804-0002/"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1991305"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T05:57:13.619089023Z"}}