Loading HuntDB...

CVE-2020-1719

UNKNOWN
Published 2021-06-07T16:23:44
Actions:

Expert Analysis

Professional remediation guidance

Get tailored security recommendations from our analyst team for CVE-2020-1719. We'll provide specific mitigation strategies based on your environment and risk profile.

No CVSS data available

Description

A flaw was found in wildfly. The EJBContext principle is not popped back after invoking another EJB using a different Security Domain. The highest threat from this vulnerability is to data confidentiality and integrity. Versions before wildfly 20.0.0.Final are affected.

Available Exploits

No exploits available for this CVE.

Related News

No news articles found for this CVE.

GitHub Security Advisories

Community-driven vulnerability intelligence from GitHub

✓ GitHub Reviewed MODERATE

Privilege Context Switching Error in wildlfy

GHSA-p9cf-qjxq-vxw6

Advisory Details

A flaw was found in wildfly. The EJBContext principle is not popped back after invoking another EJB using a different Security Domain. The highest threat from this vulnerability is to data confidentiality and integrity. Versions before wildfly 20.0.0.Final are affected.

Affected Packages

Maven org.wildfly.bom:wildfly
ECOSYSTEM: ≥0 <20.0.0.Final

CVSS Scoring

CVSS Score

5.0

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

Advisory provided by GitHub Security Advisory Database. Published: June 8, 2021, Modified: June 17, 2021

References

Published: 2021-06-07T16:23:44
Last Modified: 2024-08-04T06:46:30.328Z
Copied to clipboard!