CVE-2020-1732: Red Hat JBoss Enterprise Application Platform

Medium severity, CVSS 4.2. EPSS: 0.7% chance of exploitation in the next 30 days.

A flaw was found in Soteria before 1.0.1, in a way that multiple requests occurring concurrently causing security identity corruption across concurrent threads when using EE Security with WildFly Elytron which can lead to the possibility of being handled using the identity from another request.

Affected products

  • Red Hat JBoss Enterprise Application Platform: version 7.0.0 only
  • Red Hat JBoss Enterprise Application Platform Continuous Delivery: affected versions not specified
  • Red Hat Openshift Application Runtimes: affected versions not specified
  • Red Hat Soteria: before 1.0.1 (fixed in 1.0.1)

Published 2020-05-04. Last modified 2026-06-17.