Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2012-2312

Опубликовано: 30 апр. 2012
Источник: redhat
CVSS2: 3.3

Описание

An Elevated Privileges issue exists in JBoss AS 7 Community Release due to the improper implementation in the security context propagation, A threat gets reused from the thread pool that still retains the security context from the process last used, which lets a local user obtain elevated privileges.

Отчет

This flaw does not affect any Red Hat JBoss products, it only affects the JBoss AS 7 community releases.

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=8188377: Security Context Propagation - When re-using thread from thread pool, security context also gets re-used

3.3 Low

CVSS2

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 6 лет назад

An Elevated Privileges issue exists in JBoss AS 7 Community Release due to the improper implementation in the security context propagation, A threat gets reused from the thread pool that still retains the security context from the process last used, which lets a local user obtain elevated privileges.

CVSS3: 7.8
nvd
больше 6 лет назад

An Elevated Privileges issue exists in JBoss AS 7 Community Release due to the improper implementation in the security context propagation, A threat gets reused from the thread pool that still retains the security context from the process last used, which lets a local user obtain elevated privileges.

CVSS3: 7.8
debian
больше 6 лет назад

An Elevated Privileges issue exists in JBoss AS 7 Community Release du ...

github
больше 4 лет назад

An Elevated Privileges issue exists in JBoss AS 7 Community Release due to the improper implementation in the security context propagation, A threat gets reused from the thread pool that still retains the security context from the process last used, which lets a local user obtain elevated privileges.

3.3 Low

CVSS2