Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8674-26jc-wh98

Опубликовано: 09 фев. 2022
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

Improper Access Control in infinispan-server-runtime

A flaw was found in infinispan 10 REST API, where authorization permissions are not checked while performing some server management operations. When authz is enabled, any user with authentication can perform operations like shutting down the server without the ADMIN role.

Пакеты

Наименование

org.infinispan:infinispan-core

maven
Затронутые версииВерсия исправления

<= 11.0.5.Final

11.0.6.Final

EPSS

Процентиль: 40%
0.00183
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-269
CWE-862

Связанные уязвимости

CVSS3: 5.9
redhat
около 5 лет назад

A flaw was found in infinispan 10 REST API, where authorization permissions are not checked while performing some server management operations. When authz is enabled, any user with authentication can perform operations like shutting down the server without the ADMIN role.

CVSS3: 6.5
nvd
около 5 лет назад

A flaw was found in infinispan 10 REST API, where authorization permissions are not checked while performing some server management operations. When authz is enabled, any user with authentication can perform operations like shutting down the server without the ADMIN role.

EPSS

Процентиль: 40%
0.00183
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-269
CWE-862