Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7hpw-qq87-9462

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

It was discovered that the ElytronManagedThread in Wildfly's Elytron subsystem in versions from 11 to 16 stores a SecurityIdentity to run the thread as. These threads do not necessarily terminate if the keep alive time has not expired. This could allow a shared thread to use the wrong security identity when executing.

It was discovered that the ElytronManagedThread in Wildfly's Elytron subsystem in versions from 11 to 16 stores a SecurityIdentity to run the thread as. These threads do not necessarily terminate if the keep alive time has not expired. This could allow a shared thread to use the wrong security identity when executing.

EPSS

Процентиль: 79%
0.01229
Низкий

Связанные уязвимости

CVSS3: 5.4
redhat
почти 7 лет назад

It was discovered that the ElytronManagedThread in Wildfly's Elytron subsystem in versions from 11 to 16 stores a SecurityIdentity to run the thread as. These threads do not necessarily terminate if the keep alive time has not expired. This could allow a shared thread to use the wrong security identity when executing.

CVSS3: 8.8
nvd
почти 7 лет назад

It was discovered that the ElytronManagedThread in Wildfly's Elytron subsystem in versions from 11 to 16 stores a SecurityIdentity to run the thread as. These threads do not necessarily terminate if the keep alive time has not expired. This could allow a shared thread to use the wrong security identity when executing.

CVSS3: 8.8
debian
почти 7 лет назад

It was discovered that the ElytronManagedThread in Wildfly's Elytron s ...

CVSS3: 5.4
fstec
почти 7 лет назад

Уязвимость Java-сервера приложений WildFly, связанная с ошибками реализации проверки безопасности для стандартных элементов, позволяющая нарушителю оказать воздействие на конфиденциальность и целостность защищаемой информации

EPSS

Процентиль: 79%
0.01229
Низкий