Uploaded image for project: 'PicketBox '
  1. PicketBox
  2. SECURITY-845

Classloader leak in JBossCachedAuthenticationManager

    XMLWordPrintable

Details

    • Bug
    • Resolution: Done
    • Major
    • PicketBox_4_0_21.Final
    • PicketBox_4_0_21.Beta2
    • PicketBox
    • None

    Description

      The problematic piece of code is the domainCache member variable which in the DomainInfo value holds a LoginContext instance. This LoginContext has member contextClassLoader which causes the leak. (It points to the ModuleClassLoader of the deployment).

      Attachments

        Issue Links

          Activity

            People

              ehugonne1@redhat.com Emmanuel Hugonnet
              ehugonne1@redhat.com Emmanuel Hugonnet
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: