First published: Mon Feb 25 2019(Updated: )
A flaw was found in Wildfly from version 11. The ElytronManagedThread in Elytron subsystem stores a SecurityIdentity to run the thread as. These threads do not necessarily terminate if the keep alive time has not expired. This could cause a shared thread to use the wrong security identity when executing.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/eap7-activemq-artemis | <0:2.6.3-5.redhat_00020.1.el6ea | 0:2.6.3-5.redhat_00020.1.el6ea |
redhat/eap7-apache-commons-lang | <0:3.8.0-1.redhat_00001.1.el6ea | 0:3.8.0-1.redhat_00001.1.el6ea |
redhat/eap7-apache-cxf | <0:3.2.7-1.redhat_00001.1.el6ea | 0:3.2.7-1.redhat_00001.1.el6ea |
redhat/eap7-apache-cxf-xjc-utils | <0:3.2.3-2.redhat_00002.1.el6ea | 0:3.2.3-2.redhat_00002.1.el6ea |
redhat/eap7-artemis-native | <0:2.6.3-15.redhat_00020.el6ea | 0:2.6.3-15.redhat_00020.el6ea |
redhat/eap7-byte-buddy | <0:1.9.5-1.redhat_00001.1.el6ea | 0:1.9.5-1.redhat_00001.1.el6ea |
redhat/eap7-dom4j | <0:2.1.1-2.redhat_00001.1.el6ea | 0:2.1.1-2.redhat_00001.1.el6ea |
redhat/eap7-elytron-web | <0:1.2.4-1.Final_redhat_00001.1.el6ea | 0:1.2.4-1.Final_redhat_00001.1.el6ea |
redhat/eap7-hibernate | <0:5.3.9-2.Final_redhat_00002.1.el6ea | 0:5.3.9-2.Final_redhat_00002.1.el6ea |
redhat/eap7-httpcomponents-asyncclient | <0:4.1.4-1.redhat_00001.1.el6ea | 0:4.1.4-1.redhat_00001.1.el6ea |
redhat/eap7-infinispan | <0:9.3.6-1.Final_redhat_00001.1.el6ea | 0:9.3.6-1.Final_redhat_00001.1.el6ea |
redhat/eap7-ironjacamar | <0:1.4.15-1.Final_redhat_00001.1.el6ea | 0:1.4.15-1.Final_redhat_00001.1.el6ea |
redhat/eap7-jackson-annotations | <0:2.9.8-2.redhat_00004.1.el6ea | 0:2.9.8-2.redhat_00004.1.el6ea |
redhat/eap7-jackson-core | <0:2.9.8-2.redhat_00004.1.el6ea | 0:2.9.8-2.redhat_00004.1.el6ea |
redhat/eap7-jackson-databind | <0:2.9.8-2.redhat_00004.1.el6ea | 0:2.9.8-2.redhat_00004.1.el6ea |
redhat/eap7-jackson-jaxrs-providers | <0:2.9.8-2.redhat_00004.1.el6ea | 0:2.9.8-2.redhat_00004.1.el6ea |
redhat/eap7-jackson-modules-base | <0:2.9.8-1.redhat_00004.1.el6ea | 0:2.9.8-1.redhat_00004.1.el6ea |
redhat/eap7-jackson-modules-java8 | <0:2.9.8-1.redhat_00004.1.el6ea | 0:2.9.8-1.redhat_00004.1.el6ea |
redhat/eap7-jberet | <0:1.3.2-1.Final_redhat_00001.1.el6ea | 0:1.3.2-1.Final_redhat_00001.1.el6ea |
redhat/eap7-jboss-ejb-client | <0:4.0.15-1.Final_redhat_00001.1.el6ea | 0:4.0.15-1.Final_redhat_00001.1.el6ea |
redhat/eap7-jboss-genericjms | <0:2.0.1-2.Final_redhat_00002.1.el6ea | 0:2.0.1-2.Final_redhat_00002.1.el6ea |
redhat/eap7-jboss-logmanager | <0:2.1.7-3.Final_redhat_00001.1.el6ea | 0:2.1.7-3.Final_redhat_00001.1.el6ea |
redhat/eap7-jboss-remoting-jmx | <0:3.0.1-1.Final_redhat_00001.1.el6ea | 0:3.0.1-1.Final_redhat_00001.1.el6ea |
redhat/eap7-jboss-security-negotiation | <0:3.0.5-2.Final_redhat_00001.1.el6ea | 0:3.0.5-2.Final_redhat_00001.1.el6ea |
redhat/eap7-jboss-server-migration | <0:1.3.0-7.Final_redhat_00004.1.el6ea | 0:1.3.0-7.Final_redhat_00004.1.el6ea |
redhat/eap7-narayana | <0:5.9.1-1.Final_redhat_00001.1.el6ea | 0:5.9.1-1.Final_redhat_00001.1.el6ea |
redhat/eap7-picketlink-bindings | <0:2.5.5-16.SP12_redhat_4.1.el6ea | 0:2.5.5-16.SP12_redhat_4.1.el6ea |
redhat/eap7-picketlink-federation | <0:2.5.5-16.SP12_redhat_4.1.el6ea | 0:2.5.5-16.SP12_redhat_4.1.el6ea |
redhat/eap7-resteasy | <0:3.6.1-4.SP3_redhat_00001.1.el6ea | 0:3.6.1-4.SP3_redhat_00001.1.el6ea |
redhat/eap7-sun-istack-commons | <0:3.0.7-2.redhat_00001.1.el6ea | 0:3.0.7-2.redhat_00001.1.el6ea |
redhat/eap7-undertow | <0:2.0.19-1.Final_redhat_00001.1.el6ea | 0:2.0.19-1.Final_redhat_00001.1.el6ea |
redhat/eap7-undertow-jastow | <0:2.0.7-2.Final_redhat_00001.1.el6ea | 0:2.0.7-2.Final_redhat_00001.1.el6ea |
redhat/eap7-wildfly | <0:7.2.1-6.GA_redhat_00004.1.el6ea | 0:7.2.1-6.GA_redhat_00004.1.el6ea |
redhat/eap7-wildfly-elytron | <0:1.6.2-1.Final_redhat_00001.1.el6ea | 0:1.6.2-1.Final_redhat_00001.1.el6ea |
redhat/eap7-wildfly-elytron-tool | <0:1.4.1-1.Final_redhat_00001.1.el6ea | 0:1.4.1-1.Final_redhat_00001.1.el6ea |
redhat/eap7-wildfly-http-client | <0:1.0.13-1.Final_redhat_00001.1.el6ea | 0:1.0.13-1.Final_redhat_00001.1.el6ea |
redhat/eap7-wildfly-transaction-client | <0:1.1.3-1.Final_redhat_00001.1.el6ea | 0:1.1.3-1.Final_redhat_00001.1.el6ea |
redhat/eap7-yasson | <0:1.0.2-1.redhat_00001.1.el6ea | 0:1.0.2-1.redhat_00001.1.el6ea |
redhat/eap7-activemq-artemis | <0:2.6.3-5.redhat_00020.1.el7ea | 0:2.6.3-5.redhat_00020.1.el7ea |
redhat/eap7-apache-commons-lang | <0:3.8.0-1.redhat_00001.1.el7ea | 0:3.8.0-1.redhat_00001.1.el7ea |
redhat/eap7-apache-cxf | <0:3.2.7-1.redhat_00001.1.el7ea | 0:3.2.7-1.redhat_00001.1.el7ea |
redhat/eap7-apache-cxf-xjc-utils | <0:3.2.3-2.redhat_00002.1.el7ea | 0:3.2.3-2.redhat_00002.1.el7ea |
redhat/eap7-artemis-native | <0:2.6.3-15.redhat_00020.el7ea | 0:2.6.3-15.redhat_00020.el7ea |
redhat/eap7-byte-buddy | <0:1.9.5-1.redhat_00001.1.el7ea | 0:1.9.5-1.redhat_00001.1.el7ea |
redhat/eap7-dom4j | <0:2.1.1-2.redhat_00001.1.el7ea | 0:2.1.1-2.redhat_00001.1.el7ea |
redhat/eap7-elytron-web | <0:1.2.4-1.Final_redhat_00001.1.el7ea | 0:1.2.4-1.Final_redhat_00001.1.el7ea |
redhat/eap7-hibernate | <0:5.3.9-2.Final_redhat_00002.1.el7ea | 0:5.3.9-2.Final_redhat_00002.1.el7ea |
redhat/eap7-httpcomponents-asyncclient | <0:4.1.4-1.redhat_00001.1.el7ea | 0:4.1.4-1.redhat_00001.1.el7ea |
redhat/eap7-infinispan | <0:9.3.6-1.Final_redhat_00001.1.el7ea | 0:9.3.6-1.Final_redhat_00001.1.el7ea |
redhat/eap7-ironjacamar | <0:1.4.15-1.Final_redhat_00001.1.el7ea | 0:1.4.15-1.Final_redhat_00001.1.el7ea |
redhat/eap7-jackson-annotations | <0:2.9.8-2.redhat_00004.1.el7ea | 0:2.9.8-2.redhat_00004.1.el7ea |
redhat/eap7-jackson-core | <0:2.9.8-2.redhat_00004.1.el7ea | 0:2.9.8-2.redhat_00004.1.el7ea |
redhat/eap7-jackson-databind | <0:2.9.8-2.redhat_00004.1.el7ea | 0:2.9.8-2.redhat_00004.1.el7ea |
redhat/eap7-jackson-jaxrs-providers | <0:2.9.8-2.redhat_00004.1.el7ea | 0:2.9.8-2.redhat_00004.1.el7ea |
redhat/eap7-jackson-modules-base | <0:2.9.8-1.redhat_00004.1.el7ea | 0:2.9.8-1.redhat_00004.1.el7ea |
redhat/eap7-jackson-modules-java8 | <0:2.9.8-1.redhat_00004.1.el7ea | 0:2.9.8-1.redhat_00004.1.el7ea |
redhat/eap7-jberet | <0:1.3.2-1.Final_redhat_00001.1.el7ea | 0:1.3.2-1.Final_redhat_00001.1.el7ea |
redhat/eap7-jboss-ejb-client | <0:4.0.15-1.Final_redhat_00001.1.el7ea | 0:4.0.15-1.Final_redhat_00001.1.el7ea |
redhat/eap7-jboss-genericjms | <0:2.0.1-2.Final_redhat_00002.1.el7ea | 0:2.0.1-2.Final_redhat_00002.1.el7ea |
redhat/eap7-jboss-logmanager | <0:2.1.7-3.Final_redhat_00001.1.el7ea | 0:2.1.7-3.Final_redhat_00001.1.el7ea |
redhat/eap7-jboss-remoting-jmx | <0:3.0.1-1.Final_redhat_00001.1.el7ea | 0:3.0.1-1.Final_redhat_00001.1.el7ea |
redhat/eap7-jboss-security-negotiation | <0:3.0.5-2.Final_redhat_00001.1.el7ea | 0:3.0.5-2.Final_redhat_00001.1.el7ea |
redhat/eap7-jboss-server-migration | <0:1.3.0-7.Final_redhat_00004.1.el7ea | 0:1.3.0-7.Final_redhat_00004.1.el7ea |
redhat/eap7-narayana | <0:5.9.1-1.Final_redhat_00001.1.el7ea | 0:5.9.1-1.Final_redhat_00001.1.el7ea |
redhat/eap7-picketlink-bindings | <0:2.5.5-16.SP12_redhat_4.1.el7ea | 0:2.5.5-16.SP12_redhat_4.1.el7ea |
redhat/eap7-picketlink-federation | <0:2.5.5-16.SP12_redhat_4.1.el7ea | 0:2.5.5-16.SP12_redhat_4.1.el7ea |
redhat/eap7-resteasy | <0:3.6.1-4.SP3_redhat_00001.1.el7ea | 0:3.6.1-4.SP3_redhat_00001.1.el7ea |
redhat/eap7-sun-istack-commons | <0:3.0.7-2.redhat_00001.1.el7ea | 0:3.0.7-2.redhat_00001.1.el7ea |
redhat/eap7-undertow | <0:2.0.19-1.Final_redhat_00001.1.el7ea | 0:2.0.19-1.Final_redhat_00001.1.el7ea |
redhat/eap7-undertow-jastow | <0:2.0.7-2.Final_redhat_00001.1.el7ea | 0:2.0.7-2.Final_redhat_00001.1.el7ea |
redhat/eap7-wildfly | <0:7.2.1-6.GA_redhat_00004.1.el7ea | 0:7.2.1-6.GA_redhat_00004.1.el7ea |
redhat/eap7-wildfly-elytron | <0:1.6.2-1.Final_redhat_00001.1.el7ea | 0:1.6.2-1.Final_redhat_00001.1.el7ea |
redhat/eap7-wildfly-elytron-tool | <0:1.4.1-1.Final_redhat_00001.1.el7ea | 0:1.4.1-1.Final_redhat_00001.1.el7ea |
redhat/eap7-wildfly-http-client | <0:1.0.13-1.Final_redhat_00001.1.el7ea | 0:1.0.13-1.Final_redhat_00001.1.el7ea |
redhat/eap7-wildfly-transaction-client | <0:1.1.3-1.Final_redhat_00001.1.el7ea | 0:1.1.3-1.Final_redhat_00001.1.el7ea |
redhat/eap7-yasson | <0:1.0.2-1.redhat_00001.1.el7ea | 0:1.0.2-1.redhat_00001.1.el7ea |
Redhat Wildfly | >=11.0.0<=16.0.0 | |
Redhat Jboss Enterprise Application Platform | =7.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)