Back

MEDIUM

wildfly: Race condition on PID file allows for termination of arbitrary processes by local users

Published May 3, 2019

Description

A flaw was discovered in wildfly versions up to 16.0.0.Final that would allow local users who are able to execute init.d script to terminate arbitrary processes on the system. An attacker could exploit this by modifying the PID file in /var/run/jboss-eap/ allowing the init.d script to terminate any process as root.

Affected products

Remediation

No remediation recorded yet.

References (13)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner redhat
Published May 3, 2019
Updated Aug 4, 2024
Reserved Jan 3, 2019

CISA Vulnrichment

No data

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

Severity Moderate
Public date Apr 30, 2019
Bugzilla 1660263

ENISA EUVD

Assigner redhat
Published May 3, 2019
Updated Aug 4, 2024

GitHub

No data