Uploaded image for project: 'WildFly'
  1. WildFly
  2. WFLY-20550

(CVE-2025-2251) Block additional classes identified by security researchers as being useful in exploit gadgets

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Done
    • Icon: Blocker Blocker
    • 36.0.0.Final
    • None
    • EJB
    • None

      We've learned of additional mechanisms found by security researchers that allow for attackers on endpoints that use Java deserialization. Update the EJB remoting endpoint to block the applicable classes involved in these gadget chains.

              bstansbe@redhat.com Brian Stansberry
              bstansbe@redhat.com Brian Stansberry
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated:
                Resolved: