Back

HIGH

7: Security Context Propagation - When re-using thread from thread pool, security context also gets re-used

Published Dec 18, 2019

Description

An Elevated Privileges issue exists in JBoss AS 7 Community Release due to the improper implementation in the security context propagation, A threat gets reused from the thread pool that still retains the security context from the process last used, which lets a local user obtain elevated privileges.

Affected products

Remediation

Red Hat statement

This flaw does not affect any Red Hat JBoss products, it only affects the JBoss AS 7 community releases.

Metrics

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Dec 18, 2019
Updated Aug 6, 2024
Reserved Apr 19, 2012
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Moderate
Public date Apr 30, 2012