Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r4w2-hjmr-36m7

Опубликовано: 30 дек. 2023
Источник: github
Github: Прошло ревью
CVSS4: 7.1
CVSS3: 6.5

Описание

Infinispan REST Server's cache retrieval endpoints do not properly evaluate the necessary admin permissions

A flaw was found in Infinispan's REST, Cache retrieval endpoints do not properly evaluate the necessary admin permissions for the operation. This issue could allow an authenticated user to access information outside of their intended permissions.

Пакеты

Наименование

org.infinispan:infinispan-server-rest

maven
Затронутые версииВерсия исправления

>= 15.0.0.Dev01, < 15.0.0.Dev04

15.0.0.Dev04

Наименование

org.infinispan:infinispan-server-rest

maven
Затронутые версииВерсия исправления

< 14.0.18.Final

14.0.18.Final

EPSS

Процентиль: 28%
0.00102
Низкий

7.1 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-304

Связанные уязвимости

CVSS3: 4.3
redhat
больше 2 лет назад

A flaw was found in Infinispan's REST, Cache retrieval endpoints do not properly evaluate the necessary admin permissions for the operation. This issue could allow an authenticated user to access information outside of their intended permissions.

CVSS3: 4.3
nvd
около 2 лет назад

A flaw was found in Infinispan's REST, Cache retrieval endpoints do not properly evaluate the necessary admin permissions for the operation. This issue could allow an authenticated user to access information outside of their intended permissions.

EPSS

Процентиль: 28%
0.00102
Низкий

7.1 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-304