{"id":"CVE-2024-1233","aliases":["GHSA-v4mm-q8fv-r2w5"],"url":"https://o3.security/vulnerability/CVE-2024-1233","summary":"Eap: wildfly-elytron has a ssrf security issue","details":"A flaw was found in` JwtValidator.resolvePublicKey` in JBoss EAP, where the validator checks jku and sends a HTTP request. During this process, no whitelisting or other filtering behavior is performed on the destination URL address, which may result in a server-side request forgery (SSRF) vulnerability.","published":"2024-04-09T07:01:47.673Z","modified":"2026-07-15T01:49:17.673422444Z","cvss":{"score":7.3,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.wildfly.security:wildfly-elytron-realm-token","fixedVersion":null}],"fix":{"url":"https://github.com/wildfly/wildfly/pull/17812/commits/0c02350bc0d84287bed46e7c32f90b36e50d3523","label":"wildfly/wildfly#17812"},"references":[{"type":"WEB","url":"https://access.redhat.com/downloads/content/package-browser/"},{"type":"WEB","url":"https://access.redhat.com/jbossnetwork/restricted/listSoftware.html"},{"type":"WEB","url":"https://github.com/wildfly/wildfly/pull/17812/commits/0c02350bc0d84287bed46e7c32f90b36e50d3523"},{"type":"WEB","url":"https://issues.redhat.com/browse/WFLY-19226"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2024:3559"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2024:3560"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2024:3561"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2024:3563"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2024:3580"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2024:3581"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2024:3583"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2025:9582"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2025:9583"},{"type":"ADVISORY","url":"https://access.redhat.com/security/cve/CVE-2024-1233"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/1xxx/CVE-2024-1233.json"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-v4mm-q8fv-r2w5"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-1233"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2262849"},{"type":"PACKAGE","url":"https://github.com/wildfly/wildfly"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T01:49:17.673422444Z"}}