Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-1732

Опубликовано: 04 мая 2020
Источник: nvd
CVSS3: 4.2
CVSS2: 4.9
EPSS Низкий

Описание

A flaw was found in Soteria before 1.0.1, in a way that multiple requests occurring concurrently causing security identity corruption across concurrent threads when using EE Security with WildFly Elytron which can lead to the possibility of being handled using the identity from another request.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:redhat:soteria:*:*:*:*:*:*:*:*
Версия до 1.0.1 (исключая)
Конфигурация 2

Одно из

cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.0.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_enterprise_application_platform_continuous_delivery:-:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openshift_application_runtimes:-:*:*:*:*:*:*:*

EPSS

Процентиль: 33%
0.00132
Низкий

4.2 Medium

CVSS3

4.9 Medium

CVSS2

Дефекты

CWE-284
CWE-20

Связанные уязвимости

CVSS3: 4.2
redhat
почти 6 лет назад

A flaw was found in Soteria before 1.0.1, in a way that multiple requests occurring concurrently causing security identity corruption across concurrent threads when using EE Security with WildFly Elytron which can lead to the possibility of being handled using the identity from another request.

CVSS3: 4.2
debian
почти 6 лет назад

A flaw was found in Soteria before 1.0.1, in a way that multiple reque ...

github
больше 3 лет назад

A flaw was found in Soteria before 1.0.1, in a way that multiple requests occurring concurrently causing security identity corruption across concurrent threads when using EE Security with WildFly Elytron which can lead to the possibility of being handled using the identity from another request.

EPSS

Процентиль: 33%
0.00132
Низкий

4.2 Medium

CVSS3

4.9 Medium

CVSS2

Дефекты

CWE-284
CWE-20