Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-1732

Опубликовано: 14 фев. 2020
Источник: redhat
CVSS3: 4.2
EPSS Низкий

Описание

A flaw was found in Soteria before 1.0.1, in a way that multiple requests occurring concurrently causing security identity corruption across concurrent threads when using EE Security with WildFly Elytron which can lead to the possibility of being handled using the identity from another request.

A flaw was found in WildFly where multiple requests occurring concurrently could be handled using the identity of another request. This vulnerability occurs when using EE Security with WildFly Elytron. The largest threat from this vulnerability is data confidentiality and integrity.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Decision Manager 7wildflyNot affected
Red Hat Fuse 7wildflyNot affected
Red Hat JBoss Data Grid 7wildflyNot affected
Red Hat JBoss Data Virtualization 6jbossasOut of support scope
Red Hat JBoss Data Virtualization 6wildflyOut of support scope
Red Hat JBoss Enterprise Application Platform 5jbossasOut of support scope
Red Hat JBoss Enterprise Application Platform 6jbossasOut of support scope
Red Hat JBoss Fuse 6wildflyOut of support scope
Red Hat JBoss Operations Network 3wildflyOut of support scope
Red Hat JBoss SOA Platform 5jbossasOut of support scope

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-284
https://bugzilla.redhat.com/show_bug.cgi?id=1801726Soteria: security identity corruption across concurrent threads

EPSS

Процентиль: 33%
0.00132
Низкий

4.2 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.2
nvd
почти 6 лет назад

A flaw was found in Soteria before 1.0.1, in a way that multiple requests occurring concurrently causing security identity corruption across concurrent threads when using EE Security with WildFly Elytron which can lead to the possibility of being handled using the identity from another request.

CVSS3: 4.2
debian
почти 6 лет назад

A flaw was found in Soteria before 1.0.1, in a way that multiple reque ...

github
больше 3 лет назад

A flaw was found in Soteria before 1.0.1, in a way that multiple requests occurring concurrently causing security identity corruption across concurrent threads when using EE Security with WildFly Elytron which can lead to the possibility of being handled using the identity from another request.

EPSS

Процентиль: 33%
0.00132
Низкий

4.2 Medium

CVSS3