Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-ppg2-ww3w-hq84

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью

Описание

User confusion in IronJacamar

The IronJacamar container before 1.0.12.Final for JBoss Application Server, when allow-multiple-users is enabled in conjunction with a security domain, does not use the credentials supplied in a getConnection function call, which allows remote attackers to obtain access to an arbitrary datasource connection in opportunistic circumstances via an invalid connection attempt.

Пакеты

Наименование

org.jboss.ironjacamar:ironjacamar-jdbc

maven
Затронутые версииВерсия исправления

< 1.0.12.Final

1.0.12.Final

EPSS

Процентиль: 67%
0.00546
Низкий

Связанные уязвимости

redhat
около 13 лет назад

The IronJacamar container before 1.0.12.Final for JBoss Application Server, when allow-multiple-users is enabled in conjunction with a security domain, does not use the credentials supplied in a getConnection function call, which allows remote attackers to obtain access to an arbitrary datasource connection in opportunistic circumstances via an invalid connection attempt.

nvd
около 13 лет назад

The IronJacamar container before 1.0.12.Final for JBoss Application Server, when allow-multiple-users is enabled in conjunction with a security domain, does not use the credentials supplied in a getConnection function call, which allows remote attackers to obtain access to an arbitrary datasource connection in opportunistic circumstances via an invalid connection attempt.

debian
около 13 лет назад

The IronJacamar container before 1.0.12.Final for JBoss Application Se ...

EPSS

Процентиль: 67%
0.00546
Низкий