CVE-2012-2312

Severity
7.8HIGH
EPSS
0.0%
top 87.22%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 18
Latest updateApr 23

Description

An Elevated Privileges issue exists in JBoss AS 7 Community Release due to the improper implementation in the security context propagation, A threat gets reused from the thread pool that still retains the security context from the process last used, which lets a local user obtain elevated privileges.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages3 packages

CVEListV5jboss_as_7/jbossAS 7 Community Release

🔴Vulnerability Details

2
GHSA
GHSA-c9m2-844r-3389: An Elevated Privileges issue exists in JBoss AS 7 Community Release due to the improper implementation in the security context propagation, A threat g2022-04-23
CVEList
CVE-2012-2312: An Elevated Privileges issue exists in JBoss AS 7 Community Release due to the improper implementation in the security context propagation, A threat g2019-12-18

📋Vendor Advisories

2
Red Hat
Mozilla: Improper character decoding in HZ-GB-2312 charset (MFSA 2012-101)2012-11-20
Red Hat
7: Security Context Propagation - When re-using thread from thread pool, security context also gets re-used2012-04-30

💬Community

2
Bugzilla
CVE-2012-4207 Mozilla: Improper character decoding in HZ-GB-2312 charset (MFSA 2012-101)2012-11-17
Bugzilla
CVE-2012-2312 JBoss AS 7: Security Context Propagation - When re-using thread from thread pool, security context also gets re-used2012-05-04