CVE-2019-3894
wildfly: wrong SecurityIdentity for EE concurrency threads that are reused
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
It was discovered that the ElytronManagedThread in Wildfly's Elytron subsystem in versions from 11 to 16 stores a SecurityIdentity to run the thread as. These threads do not necessarily terminate if the keep alive time has not expired. This could allow a shared thread to use the wrong security identity when executing.
Se descubrió que ElytronManagedThread del subsistemas Wildfly's Elytron en versiones desde 11 hasta la 16 almacena un SecurityIdentity para ejecutar el hilo. Estos hilos no necesariamente terminan si el tiempo de mantener activos no ha expirado. Esto podrÃa permitir compartir el hilo para emplear una identidad de seguridad incorrecta al ejecutarse.
It was discovered that the ElytronManagedThread in Wildfly's Elytron subsystem stores a SecurityIdentity to run the thread with that security identity. As these threads do not necessarily terminate if the 'keep alive' time has not expired, this could allow a shared thread to use the wrong security identity when executing.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-01-03 CVE Reserved
- 2019-05-03 CVE Published
- 2024-08-04 CVE Updated
- 2024-09-23 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-358: Improperly Implemented Security Check for Standard
CAPEC
References (8)
URL | Tag | Source |
---|---|---|
https://security.netapp.com/advisory/ntap-20190517-0004 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://access.redhat.com/errata/RHSA-2019:1106 | 2020-10-15 | |
https://access.redhat.com/errata/RHSA-2019:1107 | 2020-10-15 | |
https://access.redhat.com/errata/RHSA-2019:1108 | 2020-10-15 | |
https://access.redhat.com/errata/RHSA-2019:1140 | 2020-10-15 | |
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3894 | 2020-10-15 | |
https://access.redhat.com/security/cve/CVE-2019-3894 | 2019-05-09 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1682108 | 2019-05-09 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Redhat Search vendor "Redhat" | Wildfly Search vendor "Redhat" for product "Wildfly" | >= 11.0.0 <= 16.0.0 Search vendor "Redhat" for product "Wildfly" and version " >= 11.0.0 <= 16.0.0" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Jboss Enterprise Application Platform Search vendor "Redhat" for product "Jboss Enterprise Application Platform" | 7.0.0 Search vendor "Redhat" for product "Jboss Enterprise Application Platform" and version "7.0.0" | - |
Affected
|