A flaw was found in the HAL Console in the Wildfly component, which does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output used as a web page that is served to other users. The attacker must be authenticated as a user that belongs to management groups “SuperUser”, “Admin”, or “Maintainer”.
References
Link | Resource |
---|---|
https://access.redhat.com/security/cve/CVE-2025-23366 | Vendor Advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=2337619 | Vendor Advisory |
Configurations
History
14 Oct 2025, 17:54
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
CPE | cpe:2.3:a:redhat:hal_management_console:*:*:*:*:*:*:*:* | |
First Time |
Redhat
Redhat hal Management Console |
|
References | () https://access.redhat.com/security/cve/CVE-2025-23366 - Vendor Advisory | |
References | () https://bugzilla.redhat.com/show_bug.cgi?id=2337619 - Vendor Advisory |
14 Jan 2025, 18:16
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-01-14 18:16
Updated : 2025-10-14 17:54
NVD link : CVE-2025-23366
Mitre link : CVE-2025-23366
CVE.ORG link : CVE-2025-23366
JSON object : View
Products Affected
redhat
- hal_management_console
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')