A vulnerability was found in Wildfly's management interface. Due to the lack of limitation of sockets for the management interface it may be possible to cause a denial of service hitting the nofile limit as there is no possibility to configure or set a maximum number of connections., Red Hat WildFly Management Interface Missing Socket Limitation Connection Exhaustion Local DoS. Red Hat WildFly contains a flaw in the management interface as the number of socket is not limited. This may allow a local attacker to exhaust available connections and cause a denial of service.
Recommended Remediation: For more information regarding this CVE, as well as, patch/remediation details, it is recommended to leverage the following resources:
https://web.nvd.nist.gov/view/vuln/search
https://www.cvedetails.com/
https://cve.mitre.org/
https://www.google.com/
Severity: Low
CVSS Score: 1.2
CVE-ID: CVE-2024-4029
DevTest 10.7.2 SPx
Vulnerability
As per engineering team analysis, the specific component affected with this vulnerability is Wildfly-domain-http. However, DevTest is not this in the packs. Since this has been reported on a service pack release, this vulnerability doesn't impact the DevTest installation. Also, Black Duck vulnerability scanning tool does not indicate that we are vulnerable.