CVE-2020-1719
published 2021-06-07CVE-2020-1719: A flaw was found in wildfly. The EJBContext principle is not popped back after invoking another EJB using a different Security Domain. The highest threat from…
PriorityP429medium5.4CVSS 3.1
AVNACLPRLUINSUCLILAN
EPSS
0.57%
43.6th percentile
A flaw was found in wildfly. The EJBContext principle is not popped back after invoking another EJB using a different Security Domain. The highest threat from this vulnerability is to data confidentiality and integrity. Versions before wildfly 20.0.0.Final are affected.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | wildfly | < 20.0.0 | 20.0.0 |
| redhat | wildfly | — | — |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
nvdv2.05.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:N
vendor_redhat5.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Privilege Context Switching Error in wildlfy
ghsa·2021-06-08
CVE-2020-1719 [MEDIUM] CWE-270 Privilege Context Switching Error in wildlfy
Privilege Context Switching Error in wildlfy
A flaw was found in wildfly. The EJBContext principle is not popped back after invoking another EJB using a different Security Domain. The highest threat from this vulnerability is to data confidentiality and integrity. Versions before wildfly 20.0.0.Final are affected.
OSV
Privilege Context Switching Error in wildlfy
osv·2021-06-08
CVE-2020-1719 [MEDIUM] Privilege Context Switching Error in wildlfy
Privilege Context Switching Error in wildlfy
A flaw was found in wildfly. The EJBContext principle is not popped back after invoking another EJB using a different Security Domain. The highest threat from this vulnerability is to data confidentiality and integrity. Versions before wildfly 20.0.0.Final are affected.
Red Hat
Wildfly: EJBContext principal is not popped back after invoking another EJB using a different Security Domain
vendor_redhat·2019-06-18·CVSS 5.4
CVE-2020-1719 [MEDIUM] CWE-270 Wildfly: EJBContext principal is not popped back after invoking another EJB using a different Security Domain
Wildfly: EJBContext principal is not popped back after invoking another EJB using a different Security Domain
A flaw was found in wildfly. The EJBContext principle is not popped back after invoking another EJB using a different Security Domain. The highest threat from this vulnerability is to data confidentiality and integrity. Versions before wildfly 20.0.0.Final are affected.
A flaw was found in wildfly. The EJBContext principle is not popped back after invoking another EJB using a different Security Domain. The highest threat from this vulnerability is to data confidentiality and integrity.
Package: wildfly (Red Hat Decision Manager 7) - Not affected
Package: jbossas (Red Hat JBoss Data Virtualization 6) - Out of support scope
Package: wildfly (Red Hat JBoss Data Virtualization 6)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-27758 ImageMagick: outside the range of representable values of type 'unsigned long long' at coders/txt.c
bugzilla·2020-11-03·CVSS 3.3
CVE-2020-27758 [LOW] CVE-2020-27758 ImageMagick: outside the range of representable values of type 'unsigned long long' at coders/txt.c
CVE-2020-27758 ImageMagick: outside the range of representable values of type 'unsigned long long' at coders/txt.c
In ImageMagick, there are outside the range of representable values of type 'unsigned long long' bugs at coders/txt.c.
Reference:
https://github.com/ImageMagick/ImageMagick/issues/1719
Upstream patch:
https://github.com/ImageMagick/ImageMagick/commit/f0a8d407b2801174fd8923941a9e7822f7f9a506
Discussion:
Acknowledgments:
Name: Suhwan Song (Seoul National University)
---
In the txt coder at /coders/txt.c, ReadTXTImage() computes pixel values that could land outside the range of type unsigned long long due to improper max constraints. This flaw can be triggered when ImageMagick processes crafted input under certain conditions. Red Hat Product Security marked this as Low be
Bugzilla
CVE-2020-1719 Wildfly: EJBContext principal is not popped back after invoking another EJB using a different Security Domain
bugzilla·2020-01-30·CVSS 5.4
CVE-2020-1719 [MEDIUM] CVE-2020-1719 Wildfly: EJBContext principal is not popped back after invoking another EJB using a different Security Domain
CVE-2020-1719 Wildfly: EJBContext principal is not popped back after invoking another EJB using a different Security Domain
A flaw was found in Jboss EAP 7. The EJBContext principal is not popped back after invoking another EJB using a different Security Domain.
References:
https://issues.redhat.com/browse/JBEAP-17430
Discussion:
This issue has been addressed in the following products:
Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6
Via RHSA-2020:2058 https://access.redhat.com/errata/RHSA-2020:2058
---
This issue has been addressed in the following products:
Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7
Via RHSA-2020:2059 https://access.redhat.com/errata/RHSA-2020:2059
---
This issue has been addressed in the following products:
Red Hat JBoss Enter
2021-06-07
Published