ZeroHour

CVE-2020-1732

CVSS 3.1
4.2 medium
EPSS
<1%p50
Published
()
Modified
Description

A flaw was found in Soteria before 1.0.1, in a way that multiple requests occurring concurrently causing security identity corruption across concurrent threads when using EE Security with WildFly Elytron which can lead to the possibility of being handled using the identity from another request.

Vendors
redhat
Products
soteria, jboss enterprise application platform, jboss enterprise application platform continuous delivery, openshift application runtimes
Weakness
CWE-284, CWE-20
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.