Description
A flaw was found in wildfly. The EJBContext principle is not popped back after invoking another EJB using a different Security Domain. The highest threat from this vulnerability is to data confidentiality and integrity. Versions before wildfly 20.0.0.Final are affected.
Remediation
References
https://bugzilla.redhat.com/show_bug.cgi?id=1796617
Related Vulnerabilities
CVE-2021-21347 Vulnerability in maven package com.thoughtworks.xstream:xstream
CVE-2020-6452 Vulnerability in maven package org.webjars.npm:electron
CVE-2019-14517 Vulnerability in maven package org.webjars.bowergithub.pandao:editor.md
CVE-2020-2287 Vulnerability in maven package org.jenkins-ci.plugins:audit-trail