CVE-2020-1732Improper Access Control in Redhat Soteria

Severity
4.2MEDIUMNVD
EPSS
0.1%
top 67.23%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 4
Latest updateMay 24

Description

A flaw was found in Soteria before 1.0.1, in a way that multiple requests occurring concurrently causing security identity corruption across concurrent threads when using EE Security with WildFly Elytron which can lead to the possibility of being handled using the identity from another request.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:NExploitability: 1.6 | Impact: 2.5

Affected Packages3 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-4x5f-xw5j-gv58: A flaw was found in Soteria before 12022-05-24
CVEList
CVE-2020-1732: A flaw was found in Soteria before 12020-05-04

📋Vendor Advisories

1
Red Hat
Soteria: security identity corruption across concurrent threads2020-02-14

💬Community

2
Bugzilla
CVE-2020-25676 ImageMagick: outside the range of representable values of type 'long' and integer overflow at MagickCore/pixel.c and MagickCore/cache.c2020-10-27
Bugzilla
CVE-2020-1732 Soteria: security identity corruption across concurrent threads2020-02-11
CVE-2020-1732 — Improper Access Control in Redhat | cvebase