← Back to CVE List

CVE-2019-3894

Published: 2019-05-03T20:29Z
Last Modified: 2024-11-21T04:42Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
It was discovered that the ElytronManagedThread in Wildfly's Elytron subsystem in versions from 11 to 16 stores a SecurityIdentity to run the thread as. These threads do not necessarily terminate if the keep alive time has not expired. This could allow a shared thread to use the wrong security identity when executing. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt