CVE-2020-1732 MEDIUM

CVE-2020-1732

Vendor Red Hat
Product Soteria
Weakness CWE-284
Published May 4, 2020
Last update August 4, 2024

CVSS base score

4.2/10
Attack vector Network
Attack complexity High
Privileges required Low
User interaction None
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N

What the vulnerability does

01Description

A flaw was found in Soteria before 1.0.1, in a way that multiple requests occurring concurrently causing security identity corruption across concurrent threads when using EE Security with WildFly Elytron which can lead to the possibility of being handled using the identity from another request.

Key dates

02Disclosure timeline

May 4, 2020 CVE published
August 4, 2024 Record updated