PT-2015-4009 · Red Hat · Jboss Weld

Published

2015-02-13

·

Updated

2020-06-10

·

CVE-2014-8122

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions JBoss Weld versions prior to 2.2.8 JBoss Weld versions 3.x prior to 3.0.0 Alpha3
Description A race condition exists, allowing remote attackers to obtain information from a previous conversation via vectors related to a stale thread state.
Recommendations For versions prior to 2.2.8, update to version 2.2.8 or later. For versions 3.x prior to 3.0.0 Alpha3, update to version 3.0.0 Alpha3 or later.

Exploit

Fix

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-8122
GHSA-338V-3958-8V8R
RHSA-2015:0216
RHSA-2015:0217
RHSA-2015:0218

Affected Products

Jboss Weld