Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-46r5-59fg-2fjc

Опубликовано: 14 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 8.8

Описание

Deserialization of Untrusted Data in Infinispan

It was found that the Hotrod client in Infinispan before 9.2.0.CR1 would unsafely read deserialized data on information from the cache. An authenticated attacker could inject a malicious object into the data cache and attain deserialization on the client, and possibly conduct further attacks.

Пакеты

Наименование

org.infinispan:infinispan-core

maven
Затронутые версииВерсия исправления

<= 9.2.0.Beta2

9.2.0.CR1

EPSS

Процентиль: 88%
0.03911
Низкий

8.8 High

CVSS3

Дефекты

CWE-502

Связанные уязвимости

CVSS3: 8
redhat
почти 8 лет назад

It was found that the Hotrod client in Infinispan before 9.2.0.CR1 would unsafely read deserialized data on information from the cache. An authenticated attacker could inject a malicious object into the data cache and attain deserialization on the client, and possibly conduct further attacks.

CVSS3: 8.8
nvd
почти 8 лет назад

It was found that the Hotrod client in Infinispan before 9.2.0.CR1 would unsafely read deserialized data on information from the cache. An authenticated attacker could inject a malicious object into the data cache and attain deserialization on the client, and possibly conduct further attacks.

EPSS

Процентиль: 88%
0.03911
Низкий

8.8 High

CVSS3

Дефекты

CWE-502