PT-2020-12297 · Red Hat · Wildfly

Guilherme De Almeida Suckevicz

·

Published

2020-09-16

·

Updated

2024-03-06

·

CVE-2020-10718

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Wildfly versions prior to 13.0.0.Final
Description A flaw was found in the embedded managed process API, where the Thread Context Classloader (TCCL) setting is exposed as a public method. This exposure can bypass the security manager, posing a threat to confidentiality.
Recommendations For versions prior to 13.0.0.Final, update to version 13.0.0.Final or later to resolve the issue. As a temporary workaround, consider restricting access to the public method that exposes the TCCL setting to minimize the risk of exploitation.

Fix

Related Identifiers

BIT-WILDFLY-2020-10718
CVE-2020-10718
RHSA-2020:3461
RHSA-2020:3462
RHSA-2020:3463
RHSA-2020:3637
RHSA-2020:3638
RHSA-2020:3639

Affected Products

Wildfly