CVE-2012-2312
published 2019-12-18CVE-2012-2312: An Elevated Privileges issue exists in JBoss AS 7 Community Release due to the improper implementation in the security context propagation, A threat gets…
PriorityP336high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.29%
21.3th percentile
An Elevated Privileges issue exists in JBoss AS 7 Community Release due to the improper implementation in the security context propagation, A threat gets reused from the thread pool that still retains the security context from the process last used, which lets a local user obtain elevated privileges.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| jboss_as_7 | jboss | — | — |
| redhat | jboss_application_server | — | — |
| redhat | jboss_application_server | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-c9m2-844r-3389: An Elevated Privileges issue exists in JBoss AS 7 Community Release due to the improper implementation in the security context propagation, A threat g
ghsa_unreviewed·2022-04-23
CVE-2012-2312 [MEDIUM] GHSA-c9m2-844r-3389: An Elevated Privileges issue exists in JBoss AS 7 Community Release due to the improper implementation in the security context propagation, A threat g
An Elevated Privileges issue exists in JBoss AS 7 Community Release due to the improper implementation in the security context propagation, A threat gets reused from the thread pool that still retains the security context from the process last used, which lets a local user obtain elevated privileges.
Red Hat
Mozilla: Improper character decoding in HZ-GB-2312 charset (MFSA 2012-101)
vendor_redhat·2012-11-20·CVSS 4.3
CVE-2012-4207 [MEDIUM] Mozilla: Improper character decoding in HZ-GB-2312 charset (MFSA 2012-101)
Mozilla: Improper character decoding in HZ-GB-2312 charset (MFSA 2012-101)
The HZ-GB-2312 character-set implementation in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 does not properly handle a ~ (tilde) character in proximity to a chunk delimiter, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted document.
Red Hat
7: Security Context Propagation - When re-using thread from thread pool, security context also gets re-used
vendor_redhat·2012-04-30·CVSS 7.8
CVE-2012-2312 [HIGH] 7: Security Context Propagation - When re-using thread from thread pool, security context also gets re-used
7: Security Context Propagation - When re-using thread from thread pool, security context also gets re-used
An Elevated Privileges issue exists in JBoss AS 7 Community Release due to the improper implementation in the security context propagation, A threat gets reused from the thread pool that still retains the security context from the process last used, which lets a local user obtain elevated privileges.
Statement: This flaw does not affect any Red Hat JBoss products, it only affects the JBoss AS 7 community releases.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-4207 Mozilla: Improper character decoding in HZ-GB-2312 charset (MFSA 2012-101)
bugzilla·2012-11-17·CVSS 4.3
CVE-2012-4207 [MEDIUM] CVE-2012-4207 Mozilla: Improper character decoding in HZ-GB-2312 charset (MFSA 2012-101)
CVE-2012-4207 Mozilla: Improper character decoding in HZ-GB-2312 charset (MFSA 2012-101)
Security researcher Masato Kinugawa found when HZ-GB-2312 charset encoding is used for text, the "~" character will destroy another character near the chunk delimiter. This can lead to a cross-site scripting (XSS) attack in pages encoded in HZ-GB-2312.
External Reference:
http://www.mozilla.org/security/announce/2012/mfsa2012-101.html
Acknowledgements:
Red Hat would like to thank the Mozilla project for reporting this issue. Upstream acknowledges Masato Kinugawa as the original reporter.
Discussion:
This issue has been addressed in following products:
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 5
Via RHSA-2012:1483 https://rhn.redhat.com/errata/RHSA-2012-1483.html
---
This issue ha
Bugzilla
CVE-2012-2312 JBoss AS 7: Security Context Propagation - When re-using thread from thread pool, security context also gets re-used
bugzilla·2012-05-04·CVSS 7.8
CVE-2012-2312 [HIGH] CVE-2012-2312 JBoss AS 7: Security Context Propagation - When re-using thread from thread pool, security context also gets re-used
CVE-2012-2312 JBoss AS 7: Security Context Propagation - When re-using thread from thread pool, security context also gets re-used
Security context propagation was not properly implemented. As a result, when a thread gets re-used from the thread pool, it still retains the security context from the process that last used it. The new security context is not properly propagated, and hence the previous security context will be in effect. A local attacker can use this flaw to escalate privileges in a malicious application deployed to the JBoss server.
Discussion:
This issue only affects JBoss AS 7.1.0, 7.1.1 and EAP 6 Beta.
---
Upstream bug: https://issues.jboss.org/browse/JBPAPP-8863
---
Statement:
This flaw does not affect any Red Hat JBoss products, it only affects the JBoss AS 7 com
https://access.redhat.com/security/cve/cve-2012-2312https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-2312https://security-tracker.debian.org/tracker/CVE-2012-2312https://access.redhat.com/security/cve/cve-2012-2312https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-2312https://security-tracker.debian.org/tracker/CVE-2012-2312
2019-12-18
Published