EXPOSURES › CVE-2010-1428
CVE-2010-1428
CRITICAL ⌖ ON CISA KEV · EXPLOITEDAn incomplete block on the JBoss Web Console allowed unauthenticated attackers to access sensitive information via HTTP verbs beyond GET and POST.
The JBoss Web Console's default protection was bypassed because it only blocked GET and POST requests, leaving other HTTP verbs exploitable for information disclosure. DIB organizations must ensure that default security controls are fully implemented and that incomplete blocks do not leave critical interfaces exposed to unauthenticated attackers. This failure highlights the risk of relying on partial mitigations and the need for comprehensive access control validation.
Shame score — A default security control was implemented incompletely, allowing unauthenticated access to sensitive data through a known vulnerability that was actively exploited in the wild.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Unauthenticated access to the JBoss Application Server Web Console (/web-console) is blocked by default. However, it was found that this block was incomplete, and only blocked GET and POST HTTP verbs. A remote attacker could use this flaw to gain access to sensitive information.
| PRODUCT | STATUS |
|---|---|
| Red Hat OpenShift Service on AWS (ROSA) Red Hat |
In Process |