CVE-2019-3894
03.05.2019, 20:29
It was discovered that the ElytronManagedThread in Wildfly's Elytron subsystem in versions from 11 to 16 stores a SecurityIdentity to run the thread as. These threads do not necessarily terminate if the keep alive time has not expired. This could allow a shared thread to use the wrong security identity when executing.Enginsight
Vendor | Product | Version |
---|---|---|
redhat | wildfly | 11.0.0 ≤ 𝑥 ≤ 16.0.0 |
redhat | jboss_enterprise_application_platform | 7.0.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References