First published: Mon Dec 01 2014(Updated: )
It was discovered that under specific conditions the conversation state information stored in a thread local variable was not cleaned correctly when the conversation ends. This could lead to a race condition which when met could potentially expose sensitive information that was visible to the previous conversation to the current one.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Jboss Weld | <=2.2.7 | |
Redhat Jboss Weld | =3.0.0-alpha1 | |
Redhat Jboss Weld | =3.0.0-alpha2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.