Lucene search

K
redhatcveRedhat.comRH:CVE-2019-3894
HistoryOct 08, 2019 - 6:01 a.m.

CVE-2019-3894

2019-10-0806:01:47
redhat.com
access.redhat.com
14

0.006 Low

EPSS

Percentile

79.2%

It was discovered that the ElytronManagedThread in Wildfly’s Elytron subsystem stores a SecurityIdentity to run the thread with that security identity. As these threads do not necessarily terminate if the ‘keep alive’ time has not expired, this could allow a shared thread to use the wrong security identity when executing.

0.006 Low

EPSS

Percentile

79.2%