Описание
A flaw was found in Soteria before 1.0.1, in a way that multiple requests occurring concurrently causing security identity corruption across concurrent threads when using EE Security with WildFly Elytron which can lead to the possibility of being handled using the identity from another request.
Ссылки
- Issue TrackingPatchVendor Advisory
- PatchThird Party Advisory
- Issue TrackingPatchVendor Advisory
- PatchThird Party Advisory
Уязвимые конфигурации
Одно из
EPSS
4.2 Medium
CVSS3
4.9 Medium
CVSS2
Дефекты
Связанные уязвимости
A flaw was found in Soteria before 1.0.1, in a way that multiple requests occurring concurrently causing security identity corruption across concurrent threads when using EE Security with WildFly Elytron which can lead to the possibility of being handled using the identity from another request.
A flaw was found in Soteria before 1.0.1, in a way that multiple reque ...
A flaw was found in Soteria before 1.0.1, in a way that multiple requests occurring concurrently causing security identity corruption across concurrent threads when using EE Security with WildFly Elytron which can lead to the possibility of being handled using the identity from another request.
EPSS
4.2 Medium
CVSS3
4.9 Medium
CVSS2