Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Race condition in JBoss Weld before 2.2.8 and 3.x before 3.0.0 Alpha3 allows remote attackers to obtain information from a previous conversation via vectors related to a stale thread state.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Red Hat JBoss Weld 竞争条件漏洞
Vulnerability Description
Red Hat JBoss Weld是美国红帽(Red Hat)公司的一个Java EE 6平台中CDI(Contexts and Dependency Injection,上下文和依赖注入)标准的实现,它提供Java框架下标准的依赖注入(DI)及组件的生命周期管理等功能。 Red Hat JBoss Weld 2.2.8之前版本和3.0.0 Alpha3之前3.x版本中存在竞争条件漏洞。远程攻击者可利用该漏洞获取旧会话的敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A