Vulnerabilities > CVE-2020-14317 - Signal Handler Race Condition vulnerability in Redhat Jboss Enterprise Application Platform and Wildfly
Attack vector
LOCAL Attack complexity
LOW Privileges required
NONE Confidentiality impact
NONE Integrity impact
NONE Availability impact
COMPLETE Summary
It was found that the issue for security flaw CVE-2019-3805 appeared again in a further version of JBoss Enterprise Application Platform - Continuous Delivery (EAP-CD) introducing regression. An attacker could exploit this by modifying the PID file in /var/run/jboss-eap/ allowing the init.d script to terminate any process as root.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 |