Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2012-2312

Опубликовано: 30 апр. 2012
Источник: redhat
CVSS2: 3.3

Описание

An Elevated Privileges issue exists in JBoss AS 7 Community Release due to the improper implementation in the security context propagation, A threat gets reused from the thread pool that still retains the security context from the process last used, which lets a local user obtain elevated privileges.

Отчет

This flaw does not affect any Red Hat JBoss products, it only affects the JBoss AS 7 community releases.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss Enterprise Web Server 1unknownNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=8188377: Security Context Propagation - When re-using thread from thread pool, security context also gets re-used

3.3 Low

CVSS2

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 6 лет назад

An Elevated Privileges issue exists in JBoss AS 7 Community Release due to the improper implementation in the security context propagation, A threat gets reused from the thread pool that still retains the security context from the process last used, which lets a local user obtain elevated privileges.

CVSS3: 7.8
nvd
около 6 лет назад

An Elevated Privileges issue exists in JBoss AS 7 Community Release due to the improper implementation in the security context propagation, A threat gets reused from the thread pool that still retains the security context from the process last used, which lets a local user obtain elevated privileges.

CVSS3: 7.8
debian
около 6 лет назад

An Elevated Privileges issue exists in JBoss AS 7 Community Release du ...

github
почти 4 года назад

An Elevated Privileges issue exists in JBoss AS 7 Community Release due to the improper implementation in the security context propagation, A threat gets reused from the thread pool that still retains the security context from the process last used, which lets a local user obtain elevated privileges.

3.3 Low

CVSS2