CVE-2020-14317

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
02/06/2021
Last modified:
10/06/2021

Description

It was found that the issue for security flaw CVE-2019-3805 appeared again in a further version of JBoss Enterprise Application Platform - Continuous Delivery (EAP-CD) introducing regression. An attacker could exploit this by modifying the PID file in /var/run/jboss-eap/ allowing the init.d script to terminate any process as root.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:redhat:jboss_enterprise_application_platform:-:*:*:*:continuous_delivery:*:*:*
cpe:2.3:a:redhat:wildfly:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools