A flaw was found in SmallRye's API through version 1.6.1. The API can allow other code running within the application server to potentially obtain the ClassLoader, bypassing any permissions checks that should have been applied. The largest threat from this vulnerability is a threat to data confidentiality. This is fixed in SmallRye 1.6.2
Advisories
Source ID Title
EUVD EUVD EUVD-2022-1318 A flaw was found in SmallRye's API through version 1.6.1. The API can allow other code running within the application server to potentially obtain the ClassLoader, bypassing any permissions checks that should have been applied. The largest threat from this vulnerability is a threat to data confidentiality. This is fixed in SmallRye 1.6.2
Github GHSA Github GHSA GHSA-54fx-gm74-q676 Permissions bypass in SmallRye
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2024-08-04T06:46:30.150Z

Reserved: 2019-11-27T00:00:00

Link: CVE-2020-1729

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-05-28T14:15:07.733

Modified: 2024-11-21T05:11:15.427

Link: CVE-2020-1729

cve-icon Redhat

Severity : Low

Publid Date: 2020-02-13T00:00:00Z

Links: CVE-2020-1729 - Bugzilla

cve-icon OpenCVE Enrichment

No data.