Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-488m-w9fp-5mm2

Опубликовано: 28 дек. 2023
Источник: github
Github: Прошло ревью
CVSS4: 7.1
CVSS3: 6.5

Описание

Infinispan circular object references causes out of memory errors

A flaw was found in Infinispan, which does not detect circular object references when unmarshalling. An authenticated attacker with sufficient permissions could insert a maliciously constructed object into the cache and use it to cause out of memory errors and achieve a denial of service.

Пакеты

Наименование

org.infinispan.protostream:protostream

maven
Затронутые версииВерсия исправления

< 4.6.2.Final

4.6.2.Final

EPSS

Процентиль: 28%
0.001
Низкий

7.1 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-1047

Связанные уязвимости

CVSS3: 4.4
redhat
больше 2 лет назад

A flaw was found in Infinispan, which does not detect circular object references when unmarshalling. An authenticated attacker with sufficient permissions could insert a maliciously constructed object into the cache and use it to cause out of memory errors and achieve a denial of service.

CVSS3: 4.4
nvd
около 2 лет назад

A flaw was found in Infinispan, which does not detect circular object references when unmarshalling. An authenticated attacker with sufficient permissions could insert a maliciously constructed object into the cache and use it to cause out of memory errors and achieve a denial of service.

EPSS

Процентиль: 28%
0.001
Низкий

7.1 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-1047