Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-1131

Опубликовано: 14 мая 2018
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Infinispan permits improper deserialization of trusted data via XML and JSON transcoders under certain server configurations. A user with authenticated access to the server could send a malicious object to a cache configured to accept certain types of objects, achieving code execution and possible further attacks. Versions 9.0.3.Final, 9.1.7.Final, 8.2.10.Final, 9.2.2.Final, 9.3.0.Alpha1 are believed to be affected.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss Data Virtualization 6infinispanOut of support scope
Red Hat JBoss Enterprise Application Platform 6infinispanNot affected
Red Hat JBoss Enterprise Application Platform 7infinispan-coreAffected
Red Hat JBoss Fuse 6camelAffected
Red Hat JBoss Fuse Service Works 6infinispanOut of support scope
Red Hat JBoss Operations Network 3infinispanNot affected
Red Hat OpenShift Application RuntimesinfinispanAffected
Red Hat Single Sign-On 7infinispanNot affected
Red Hat Data GridinfinispanFixedRHSA-2018:183312.06.2018
Red Hat Fuse 7.5.0camelFixedRHSA-2019:389214.11.2019

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-349
https://bugzilla.redhat.com/show_bug.cgi?id=1576492infinispan: deserialization of data in XML and JSON transcoders

EPSS

Процентиль: 67%
0.0053
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
nvd
больше 7 лет назад

Infinispan permits improper deserialization of trusted data via XML and JSON transcoders under certain server configurations. A user with authenticated access to the server could send a malicious object to a cache configured to accept certain types of objects, achieving code execution and possible further attacks. Versions 9.0.3.Final, 9.1.7.Final, 8.2.10.Final, 9.2.2.Final, 9.3.0.Alpha1 are believed to be affected.

CVSS3: 8.8
github
больше 3 лет назад

Deserialization of Untrusted Data in Infinispan

EPSS

Процентиль: 67%
0.0053
Низкий

7.5 High

CVSS3