CVE Published: 03/05/2019 |
CVE Updated: 04/08/2024 |
CVE Year: 2019 Source: redhat |
Vendor: Red Hat |
Product: wildfly Status : PUBLISHED
CVE-2019-3894 Description
It was discovered that the ElytronManagedThread in Wildfly\'s Elytron subsystem in versions from 11 to 16 stores a SecurityIdentity to run the thread as. These threads do not necessarily terminate if the keep alive time has not expired. This could allow a shared thread to use the wrong security identity when executing.