CVE-2019-3805
published 2019-05-03CVE-2019-3805: A flaw was discovered in wildfly versions up to 16.0.0.Final that would allow local users who are able to execute init.d script to terminate arbitrary…
PriorityP420medium4.7CVSS 3.1
AVLACHPRLUINSUCNINAH
EPSS
0.19%
8.9th percentile
A flaw was discovered in wildfly versions up to 16.0.0.Final that would allow local users who are able to execute init.d script to terminate arbitrary processes on the system. An attacker could exploit this by modifying the PID file in /var/run/jboss-eap/ allowing the init.d script to terminate any process as root.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | wildfly | <= 16.0.0 | — |
| redhat | wildfly | — | — |
CVSS provenance
nvdv3.14.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.7MEDIUMAV:L/AC:M/Au:N/C:N/I:N/A:C
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-p2p6-fgmf-hp85: It was found that the issue for security flaw CVE-2019-3805 appeared again in a further version of JBoss Enterprise Application Platform - Continuous
ghsa_unreviewed·2022-05-24·CVSS 4.7
CVE-2020-14317 [MEDIUM] CWE-364 GHSA-p2p6-fgmf-hp85: It was found that the issue for security flaw CVE-2019-3805 appeared again in a further version of JBoss Enterprise Application Platform - Continuous
It was found that the issue for security flaw CVE-2019-3805 appeared again in a further version of JBoss Enterprise Application Platform - Continuous Delivery (EAP-CD) introducing regression. An attacker could exploit this by modifying the PID file in /var/run/jboss-eap/ allowing the init.d script to terminate any process as root.
GHSA
GHSA-p2vr-qm33-hrfc: A flaw was discovered in wildfly versions up to 16
ghsa_unreviewed·2022-05-24
CVE-2019-3805 [MEDIUM] CWE-269 GHSA-p2vr-qm33-hrfc: A flaw was discovered in wildfly versions up to 16
A flaw was discovered in wildfly versions up to 16.0.0.Final that would allow local users who are able to execute init.d script to terminate arbitrary processes on the system. An attacker could exploit this by modifying the PID file in /var/run/jboss-eap/ allowing the init.d script to terminate any process as root.
Red Hat
wildfly: JBoss EAP-CD regression of CVE-2019-3805
vendor_redhat·2020-07-07·CVSS 4.7
CVE-2020-14317 [MEDIUM] CWE-364 wildfly: JBoss EAP-CD regression of CVE-2019-3805
wildfly: JBoss EAP-CD regression of CVE-2019-3805
It was found that the issue for security flaw CVE-2019-3805 appeared again in a further version of JBoss Enterprise Application Platform - Continuous Delivery (EAP-CD) introducing regression. An attacker could exploit this by modifying the PID file in /var/run/jboss-eap/ allowing the init.d script to terminate any process as root.
It was found that the issue for security flaw CVE-2019-3805, appeared again in another version of the JBoss Enterprise Application Platform - Continuous Delivery (EAP-CD) introducing regression. This flaw allows an attacker to modify the PID file in /var/run/jboss-eap/ allowing the init.d script to terminate any process as root. The highest threat from this vulnerability is to system availability.
Package: wild
Red Hat
wildfly: Race condition on PID file allows for termination of arbitrary processes by local users
vendor_redhat·2019-04-30·CVSS 4.7
CVE-2019-3805 [MEDIUM] CWE-364 wildfly: Race condition on PID file allows for termination of arbitrary processes by local users
wildfly: Race condition on PID file allows for termination of arbitrary processes by local users
A flaw was discovered in wildfly versions up to 16.0.0.Final that would allow local users who are able to execute init.d script to terminate arbitrary processes on the system. An attacker could exploit this by modifying the PID file in /var/run/jboss-eap/ allowing the init.d script to terminate any process as root.
A flaw was discovered in wildfly that would allow local users, who are able to execute init.d script, to terminate arbitrary processes on the system. An attacker could exploit this by modifying the PID file in /var/run/jboss-eap/ allowing the init.d script to terminate any process as root.
Package: wildfly (Red Hat Decision Manager 7) - Not affected
Package: jbossas (Red Hat JBos
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-14317 wildfly: JBoss EAP-CD regression of CVE-2019-3805
bugzilla·2020-07-07·CVSS 4.7
CVE-2020-14317 [MEDIUM] CVE-2020-14317 wildfly: JBoss EAP-CD regression of CVE-2019-3805
CVE-2020-14317 wildfly: JBoss EAP-CD regression of CVE-2019-3805
It was found that the issue for security flaw CVE-2019-3805 appeared again in a further version of JBoss Enterprise Application Platform - Continuous Delivery (EAP-CD) introducing regression. An attacker could exploit this by modifying the PID file in /var/run/jboss-eap/ allowing the init.d script to terminate any process as root.
Discussion:
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-14317
Bugzilla
CVE-2019-3805 wildfly: Race condition on PID file allows for termination of arbitrary processes by local users
bugzilla·2018-12-18·CVSS 4.7
CVE-2019-3805 [MEDIUM] CVE-2019-3805 wildfly: Race condition on PID file allows for termination of arbitrary processes by local users
CVE-2019-3805 wildfly: Race condition on PID file allows for termination of arbitrary processes by local users
JBoss EAP has a vulnerability that allows local users who are able to execute init.d script to terminate arbitrary process on the system. An attacker could exploit this by modifying the PID file in /var/run/jboss-eap/ allowing the init.d script to terminate any process as root.
Discussion:
Acknowledgments:
Name: Daniel Le Gall (SCRT Information Security)
---
This issue has been addressed in the following products:
Red Hat JBoss Enterprise Application Platform
Via RHSA-2019:1106 https://access.redhat.com/errata/RHSA-2019:1106
---
This issue has been addressed in the following products:
Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6
Via RHSA-2019:1107 https
https://access.redhat.com/errata/RHSA-2019:1106https://access.redhat.com/errata/RHSA-2019:1107https://access.redhat.com/errata/RHSA-2019:1108https://access.redhat.com/errata/RHSA-2019:1140https://access.redhat.com/errata/RHSA-2019:2413https://access.redhat.com/errata/RHSA-2020:0727https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3805https://security.netapp.com/advisory/ntap-20190517-0004/https://access.redhat.com/errata/RHSA-2019:1106https://access.redhat.com/errata/RHSA-2019:1107https://access.redhat.com/errata/RHSA-2019:1108https://access.redhat.com/errata/RHSA-2019:1140https://access.redhat.com/errata/RHSA-2019:2413https://access.redhat.com/errata/RHSA-2020:0727https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3805https://security.netapp.com/advisory/ntap-20190517-0004/
2019-05-03
Published