It was discovered that the ElytronManagedThread in Wildfly's Elytron subsystem in versions from 11 to 16 stores a SecurityIdentity to run the thread as. These threads do not necessarily terminate if the keep alive time has not expired. This could allow a shared thread to use the wrong security identity when executing.
Advisories
Source ID Title
EUVD EUVD EUVD-2019-13503 It was discovered that the ElytronManagedThread in Wildfly's Elytron subsystem in versions from 11 to 16 stores a SecurityIdentity to run the thread as. These threads do not necessarily terminate if the keep alive time has not expired. This could allow a shared thread to use the wrong security identity when executing.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2024-08-04T19:19:18.806Z

Reserved: 2019-01-03T00:00:00

Link: CVE-2019-3894

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-05-03T20:29:01.327

Modified: 2024-11-21T04:42:48.890

Link: CVE-2019-3894

cve-icon Redhat

Severity : Moderate

Publid Date: 2019-04-30T17:11:00Z

Links: CVE-2019-3894 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses