]
Peter Skopek resolved SECURITY-845.
-----------------------------------
Fix Version/s: PicketBox_4_0_21.Beta4
Resolution: Done
Classloader leak in JBossCachedAuthenticationManager
----------------------------------------------------
Key: SECURITY-845
URL:
https://issues.jboss.org/browse/SECURITY-845
Project: PicketBox
Issue Type: Bug
Components: PicketBox
Affects Versions: PicketBox_4_0_21.Beta2
Reporter: Emmanuel Hugonnet
Assignee: Emmanuel Hugonnet
Fix For: PicketBox_4_0_21.Beta4
The problematic piece of code is the domainCache member variable which in the DomainInfo
value holds a LoginContext instance. This LoginContext has member contextClassLoader which
causes the leak. (It points to the ModuleClassLoader of the deployment).