CVE-2014-8122
JBoss Weld < 2.2.8 - Information Disclosure via Stale Thread State
Title source: llmDescription
Race condition in JBoss Weld before 2.2.8 and 3.x before 3.0.0 Alpha3 allows remote attackers to obtain information from a previous conversation via vectors related to a stale thread state.
References (16)
Core 16
Core References
Patch x_refsource_confirm
https://github.com/weld/core/commit/29fd1107fd30579ad9bb23fae4dc3ba464205745
Patch x_refsource_confirm
https://github.com/weld/core/commit/8e413202fa1af08c09c580f444e4fd16874f9c65
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/100892
Patch x_refsource_confirm
https://github.com/weld/core/commit/6808b11cd6d97c71a2eed754ed4f955acd789086
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/74252
Vendor Advisory vendor-advisory
x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2015-0215.html
Various Sources x_refsource_misc
https://github.com/victims/victims-cve-db/blob/master/database/java/2014/8122.yaml
Vendor Advisory vendor-advisory
x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2015-0217.html
Vendor Advisory vendor-advisory
x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2015-0218.html
Vendor Advisory vendor-advisory
x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2015-0216.html
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id/1031741
Vendor Advisory vendor-advisory
x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2015-0675.html
Vendor Advisory vendor-advisory
x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2015-0773.html
Vendor Advisory vendor-advisory
x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2015-0920.html
Vendor Advisory vendor-advisory
x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2015-0850.html
Vendor Advisory vendor-advisory
x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2015-0851.html
Scores
EPSS
0.0205
EPSS Percentile
78.8%
Details
CWE
CWE-362
Status
published
Products (3)
org.jboss.weld/weld-core-bom
0 - 2.2.8Maven
redhat/jboss_weld
3.0.0 alpha1 (2 CPE variants)
redhat/jboss_weld
< 2.2.7
Published
Feb 13, 2015
Tracked Since
Feb 18, 2026