CVE-2019-3894

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
03/05/2019
Last modified:
15/10/2020

Description

It was discovered that the ElytronManagedThread in Wildfly's Elytron subsystem in versions from 11 to 16 stores a SecurityIdentity to run the thread as. These threads do not necessarily terminate if the keep alive time has not expired. This could allow a shared thread to use the wrong security identity when executing.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:redhat:wildfly:*:*:*:*:*:*:*:* 11.0.0 (including) 16.0.0 (including)
cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.0.0:*:*:*:*:*:*:*