MEDIUM · 5.3

CVE-2021-3642

A flaw was found in Wildfly Elytron in versions prior to 1.10.14.Final, prior to 1.15.5.Final and prior to 1.16.1.Final where ScramServer may be susceptible to Timing Attack if enabled. The highest th...

Vulnerability Description

A flaw was found in Wildfly Elytron in versions prior to 1.10.14.Final, prior to 1.15.5.Final and prior to 1.16.1.Final where ScramServer may be susceptible to Timing Attack if enabled. The highest threat of this vulnerability is confidentiality.

CVSS Score

5.3

MEDIUM

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
RedhatWildfly Elytron< 1.10.14
RedhatBuild Of Quarkus-
RedhatCodeready Studio12.0
RedhatData Grid8.0
RedhatDescision Manager7.0
RedhatIntegration Camel K-
RedhatIntegration Camel QuarkusAll versions
RedhatJboss Enterprise Application Platform7.0.0
RedhatJboss Enterprise Application Platform Expansion Pack-
RedhatJboss Fuse7.0.0
RedhatOpenshift Application Runtimes-
RedhatProcess Automation7.0
QuarkusQuarkus<= 2.1.4

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-3642?

CVE-2021-3642 is a vulnerability with a CVSS score of 5.3 (MEDIUM). A flaw was found in Wildfly Elytron in versions prior to 1.10.14.Final, prior to 1.15.5.Final and prior to 1.16.1.Final where ScramServer may be susceptible to Timing Attack if enabled. The highest th...

How severe is CVE-2021-3642?

CVE-2021-3642 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-3642?

Check the references section above for vendor advisories and patch information. Affected products include: Redhat Wildfly Elytron, Redhat Build Of Quarkus, Redhat Codeready Studio, Redhat Data Grid, Redhat Descision Manager.