Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mvxp-3j62-jqr6

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

Infinispan Rest API Does Not Enforce Auth Constraints

It was found that the REST API in Infinispan before version 9.0.0 did not properly enforce auth constraints. An attacker could use this vulnerability to read or modify data in the default cache or a known cache name.

Пакеты

Наименование

org.infinispan:infinispan-server-core

maven
Затронутые версииВерсия исправления

< 9.0.0

9.0.0

EPSS

Процентиль: 65%
0.00495
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 6.5
redhat
почти 9 лет назад

It was found that the REST API in Infinispan before version 9.0.0 did not properly enforce auth constraints. An attacker could use this vulnerability to read or modify data in the default cache or a known cache name.

CVSS3: 6.5
nvd
больше 7 лет назад

It was found that the REST API in Infinispan before version 9.0.0 did not properly enforce auth constraints. An attacker could use this vulnerability to read or modify data in the default cache or a known cache name.

EPSS

Процентиль: 65%
0.00495
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-287