Looking for the vulnerability index of Invicti's legacy products?
Jboss EAP Permissions, Privileges, and Access Controls Vulnerability (CVE-2019-3894) - Vulnerability Database

Jboss EAP Permissions, Privileges, and Access Controls Vulnerability (CVE-2019-3894)

Description

It was discovered that the ElytronManagedThread in Wildfly's Elytron subsystem in versions from 11 to 16 stores a SecurityIdentity to run the thread as. These threads do not necessarily terminate if the keep alive time has not expired. This could allow a shared thread to use the wrong security identity when executing.

References

Related Vulnerabilities