Thread Security Identity Flaw in Wildfly Software by Red Hat
CVE-2019-3894
5.4MEDIUM
Summary
A vulnerability has been identified in the ElytronManagedThread of Wildfly’s Elytron subsystem, affecting versions 11 through 16. This flaw allows threads to retain a SecurityIdentity beyond their intended lifecycle, particularly if the keep-alive time is not met. As a result, a shared thread may execute actions using an incorrect security identity, potentially leading to unauthorized access and execution of sensitive operations.
Affected Version(s)
wildfly affects from 11 to 16
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved