org.wildfly.core:wildfly-embedded@5.0.0.CR1 vulnerabilities

Direct Vulnerabilities

Known vulnerabilities in the org.wildfly.core:wildfly-embedded package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • M
Information Exposure

Affected versions of this package are vulnerable to Information Exposure. The embedded managed process API has an exposed setting of the Thread Context Classloader (TCCL). This setting is exposed as a public method, which can bypass the security manager. The highest threat from this vulnerability is to confidentiality.

How to fix Information Exposure?

Upgrade org.wildfly.core:wildfly-embedded to version 13.0.0.Beta5 or higher.

[,13.0.0.Beta5)