Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-3894

Опубликовано: 30 апр. 2019
Источник: redhat
CVSS3: 5.4
EPSS Низкий

Описание

It was discovered that the ElytronManagedThread in Wildfly's Elytron subsystem in versions from 11 to 16 stores a SecurityIdentity to run the thread as. These threads do not necessarily terminate if the keep alive time has not expired. This could allow a shared thread to use the wrong security identity when executing.

It was discovered that the ElytronManagedThread in Wildfly's Elytron subsystem stores a SecurityIdentity to run the thread with that security identity. As these threads do not necessarily terminate if the 'keep alive' time has not expired, this could allow a shared thread to use the wrong security identity when executing.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-358
https://bugzilla.redhat.com/show_bug.cgi?id=1682108wildfly: wrong SecurityIdentity for EE concurrency threads that are reused

EPSS

Процентиль: 79%
0.01229
Низкий

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 8.8
nvd
почти 7 лет назад

It was discovered that the ElytronManagedThread in Wildfly's Elytron subsystem in versions from 11 to 16 stores a SecurityIdentity to run the thread as. These threads do not necessarily terminate if the keep alive time has not expired. This could allow a shared thread to use the wrong security identity when executing.

CVSS3: 8.8
debian
почти 7 лет назад

It was discovered that the ElytronManagedThread in Wildfly's Elytron s ...

github
больше 3 лет назад

It was discovered that the ElytronManagedThread in Wildfly's Elytron subsystem in versions from 11 to 16 stores a SecurityIdentity to run the thread as. These threads do not necessarily terminate if the keep alive time has not expired. This could allow a shared thread to use the wrong security identity when executing.

CVSS3: 5.4
fstec
почти 7 лет назад

Уязвимость Java-сервера приложений WildFly, связанная с ошибками реализации проверки безопасности для стандартных элементов, позволяющая нарушителю оказать воздействие на конфиденциальность и целостность защищаемой информации

EPSS

Процентиль: 79%
0.01229
Низкий

5.4 Medium

CVSS3