GHSA-ppg2-ww3w-hq84

Suggest an improvement
Source
https://github.com/advisories/GHSA-ppg2-ww3w-hq84
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-ppg2-ww3w-hq84/GHSA-ppg2-ww3w-hq84.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-ppg2-ww3w-hq84
Aliases
  • CVE-2012-3428
Published
2022-05-17T05:17:01Z
Modified
2024-12-06T05:39:13.411709Z
Summary
User confusion in IronJacamar
Details

The IronJacamar container before 1.0.12.Final for JBoss Application Server, when allow-multiple-users is enabled in conjunction with a security domain, does not use the credentials supplied in a getConnection function call, which allows remote attackers to obtain access to an arbitrary datasource connection in opportunistic circumstances via an invalid connection attempt.

Database specific
{
    "nvd_published_at": "2012-12-20T12:02:00Z",
    "cwe_ids": [],
    "severity": "MODERATE",
    "github_reviewed": true,
    "github_reviewed_at": "2023-12-18T22:18:11Z"
}
References

Affected packages

Maven / org.jboss.ironjacamar:ironjacamar-jdbc

Package

Name
org.jboss.ironjacamar:ironjacamar-jdbc
View open source insights on deps.dev
Purl
pkg:maven/org.jboss.ironjacamar/ironjacamar-jdbc

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.0.12.Final

Affected versions

1.*

1.0.0.Beta5
1.0.0.Beta6
1.0.0.Beta6.1
1.0.0.CR1
1.0.0.CR2
1.0.0.CR3
1.0.0.Final
1.0.1.Final
1.0.2.Final
1.0.3.Final
1.0.4.Final
1.0.5.Final
1.0.6.Final
1.0.7.Final
1.0.8.Final
1.0.9.Final
1.0.10.Final
1.0.11.Final