VDB
RHSA-2020%3A2565
RHSA-2020%3A2565
PUBLISHED
CVSS 5.5 MEDIUM
A flaw was discovered in wildfly that would allow local users, who are able to execute init.d script, to terminate arbitrary processes on the system. An attacker could exploit this by modifying the PID file in /var/run/jboss-eap/ allowing the init.d script to terminate any process as root.
Risk Scores
CVSS 3.0
5.5
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat JBoss Enterprise Application Platform Continuous Delivery |
Timeline
- Jun 15, 2020 CVE Published
- Apr 28, 2026 Security Advisory
- Apr 28, 2026 Security Advisory
- Apr 28, 2026 Security Advisory
- May 1, 2026 Distribution Patch
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
- May 14, 2026 CVE Updated
- May 15, 2026 Distribution Patch
References
- https://bugzilla.redhat.com/show_bug.cgi?id=1735745 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1741860 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1826798 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1826805 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2020/rhsa-2020_2565.json advisory
- https://www.cve.org/CVERecord?id=CVE-2019-3805 advisory
- https://kb.cert.org/vuls/id/605641/ advisory
- https://www.nginx.com/blog/nginx-updates-mitigate-august-2019-http-2-vulnerabilities/ advisory
- https://www.cve.org/CVERecord?id=CVE-2019-9512 advisory
- https://groups.google.com/forum/#!topic/kubernetes-security-announce/wlHLHit1BqA advisory
- https://www.mail-archive.com/grpc-io@googlegroups.com/msg06408.html advisory
- https://www.cve.org/CVERecord?id=CVE-2019-9514 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-9515 advisory
- https://access.redhat.com/security/cve/CVE-2019-14838 advisory
- https://www.cve.org/CVERecord?id=CVE-2019-14838 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-14838 advisory
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14838 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-19343 advisory
- https://www.cve.org/CVERecord?id=CVE-2020-11619 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-11619 advisory
…and 27 more