Information disclosure in JBoss Weld
Moderate severity
GitHub Reviewed
Published
Jun 10, 2020
to the GitHub Advisory Database
•
Updated Jan 9, 2023
Description
Reviewed
Jun 10, 2020
Published to the GitHub Advisory Database
Jun 10, 2020
Last updated
Jan 9, 2023
Race condition in JBoss Weld before 2.2.8 and 3.x before 3.0.0 Alpha3 allows remote attackers to obtain information from a previous conversation via vectors related to a stale thread state.
References