Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-1729

Опубликовано: 13 фев. 2020
Источник: redhat
CVSS3: 4
EPSS Низкий

Описание

A flaw was found in SmallRye's API through version 1.6.1. The API can allow other code running within the application server to potentially obtain the ClassLoader, bypassing any permissions checks that should have been applied. The largest threat from this vulnerability is a threat to data confidentiality. This is fixed in SmallRye 1.6.2

A flaw was found in SmallRye's API through version 1.6.1. The API can allow other code running within the application server to potentially obtain the ClassLoader, bypassing any permissions checks that should have been applied. The largest threat from this vulnerability is a threat to data confidentiality.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Application Runtimessmallrye-configAffected
Red Hat Process Automation 7smallrye-configNot affected
Red Hat Single Sign-On 7smallrye-configNot affected
Red Hat JBoss EAP 7FixedRHSA-2020:251510.06.2020
Red Hat JBoss EAP 7.2smallrye-configFixedRHSA-2020:206111.05.2020
Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6eap7-activemq-artemisFixedRHSA-2020:205811.05.2020
Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6eap7-apache-cxfFixedRHSA-2020:205811.05.2020
Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6eap7-bouncycastleFixedRHSA-2020:205811.05.2020
Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6eap7-codehaus-jacksonFixedRHSA-2020:205811.05.2020
Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6eap7-cryptacularFixedRHSA-2020:205811.05.2020

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-863
https://bugzilla.redhat.com/show_bug.cgi?id=1802444SmallRye: SecuritySupport class is incorrectly public and contains a static method to access the current threads context class loader

EPSS

Процентиль: 11%
0.00038
Низкий

4 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.4
nvd
больше 4 лет назад

A flaw was found in SmallRye's API through version 1.6.1. The API can allow other code running within the application server to potentially obtain the ClassLoader, bypassing any permissions checks that should have been applied. The largest threat from this vulnerability is a threat to data confidentiality. This is fixed in SmallRye 1.6.2

CVSS3: 4
github
почти 4 года назад

Permissions bypass in SmallRye

EPSS

Процентиль: 11%
0.00038
Низкий

4 Medium

CVSS3