// For flags

CVE-2021-3642

wildfly-elytron: possible timing attack in ScramServer

Severity Score

5.3
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

A flaw was found in Wildfly Elytron in versions prior to 1.10.14.Final, prior to 1.15.5.Final and prior to 1.16.1.Final where ScramServer may be susceptible to Timing Attack if enabled. The highest threat of this vulnerability is confidentiality.

Se ha detectado un fallo en Wildfly Elytron en versiones anteriores a 1.10.14.Final, en versiones anteriores a la 1.15.5.Final y en versiones anteriores a la 1.16.1.Final donde ScramServer puede ser susceptible a Timing Attack si está habilitado. La mayor amenaza de esta vulnerabilidad es la confidencialidad.

A flaw was found in Wildfly Elytron where ScramServer may be susceptible to Timing Attack if enabled. The highest threat of this vulnerability is confidentiality.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None
Attack Vector
Network
Attack Complexity
Medium
Authentication
Single
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2021-07-12 CVE Reserved
  • 2021-08-05 CVE Published
  • 2023-03-08 EPSS Updated
  • 2024-08-03 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-203: Observable Discrepancy
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Redhat
Search vendor "Redhat"
Wildfly Elytron
Search vendor "Redhat" for product "Wildfly Elytron"
< 1.10.14
Search vendor "Redhat" for product "Wildfly Elytron" and version " < 1.10.14"
-
Affected
Redhat
Search vendor "Redhat"
Wildfly Elytron
Search vendor "Redhat" for product "Wildfly Elytron"
>= 1.11.0 < 1.15.5
Search vendor "Redhat" for product "Wildfly Elytron" and version " >= 1.11.0 < 1.15.5"
-
Affected
Redhat
Search vendor "Redhat"
Wildfly Elytron
Search vendor "Redhat" for product "Wildfly Elytron"
>= 1.16.0 < 1.16.1
Search vendor "Redhat" for product "Wildfly Elytron" and version " >= 1.16.0 < 1.16.1"
-
Affected
Redhat
Search vendor "Redhat"
Build Of Quarkus
Search vendor "Redhat" for product "Build Of Quarkus"
--
Affected
Redhat
Search vendor "Redhat"
Codeready Studio
Search vendor "Redhat" for product "Codeready Studio"
12.0
Search vendor "Redhat" for product "Codeready Studio" and version "12.0"
-
Affected
Redhat
Search vendor "Redhat"
Data Grid
Search vendor "Redhat" for product "Data Grid"
8.0
Search vendor "Redhat" for product "Data Grid" and version "8.0"
-
Affected
Redhat
Search vendor "Redhat"
Descision Manager
Search vendor "Redhat" for product "Descision Manager"
7.0
Search vendor "Redhat" for product "Descision Manager" and version "7.0"
-
Affected
Redhat
Search vendor "Redhat"
Integration Camel K
Search vendor "Redhat" for product "Integration Camel K"
--
Affected
Redhat
Search vendor "Redhat"
Integration Camel Quarkus
Search vendor "Redhat" for product "Integration Camel Quarkus"
*-
Affected
Redhat
Search vendor "Redhat"
Jboss Enterprise Application Platform
Search vendor "Redhat" for product "Jboss Enterprise Application Platform"
7.0.0
Search vendor "Redhat" for product "Jboss Enterprise Application Platform" and version "7.0.0"
-
Affected
Redhat
Search vendor "Redhat"
Jboss Enterprise Application Platform Expansion Pack
Search vendor "Redhat" for product "Jboss Enterprise Application Platform Expansion Pack"
--
Affected
Redhat
Search vendor "Redhat"
Jboss Fuse
Search vendor "Redhat" for product "Jboss Fuse"
7.0.0
Search vendor "Redhat" for product "Jboss Fuse" and version "7.0.0"
-
Affected
Redhat
Search vendor "Redhat"
Openshift Application Runtimes
Search vendor "Redhat" for product "Openshift Application Runtimes"
--
Affected
Redhat
Search vendor "Redhat"
Process Automation
Search vendor "Redhat" for product "Process Automation"
7.0
Search vendor "Redhat" for product "Process Automation" and version "7.0"
-
Affected
Quarkus
Search vendor "Quarkus"
Quarkus
Search vendor "Quarkus" for product "Quarkus"
<= 2.1.4
Search vendor "Quarkus" for product "Quarkus" and version " <= 2.1.4"
-
Affected