Описание
A vulnerability was found in Infinispan such that the invokeAccessibly method from the public class ReflectionUtil allows any application class to invoke private methods in any class with Infinispan's privileges. The attacker can use reflection to introduce new, malicious behavior into the application.
Отчет
Red Hat OpenStack Platform's OpenDaylight contains the vulnerable library. This library is a requirement of other dependencies (Karaf and Hibernate). Under supported deployments, the vulnerable functionality is not utilized. Based on this, no OpenDaylight versions will not be fixed.
Меры по смягчению последствий
There is no known mitigation for this issue.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Decision Manager 7 | infinispan-core | Not affected | ||
| Red Hat JBoss Data Virtualization 6 | infinispan-core | Out of support scope | ||
| Red Hat JBoss Enterprise Application Platform 6 | infinispan-core | Not affected | ||
| Red Hat JBoss Fuse Service Works 6 | infinispan-core | Out of support scope | ||
| Red Hat JBoss Operations Network 3 | infinispan-core | Affected | ||
| Red Hat OpenStack Platform 13 (Queens) | opendaylight | Will not fix | ||
| Red Hat OpenStack Platform 14 (Rocky) | opendaylight | Will not fix | ||
| Red Hat OpenStack Platform 9 (Mitaka) | opendaylight | Will not fix | ||
| Red Hat Process Automation 7 | infinispan-core | Not affected | ||
| EAP-CD 19 Tech Preview | infinispan-core | Fixed | RHSA-2020:2333 | 28.05.2020 |
Показывать по
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
Связанные уязвимости
A vulnerability was found in Infinispan such that the invokeAccessibly method from the public class ReflectionUtil allows any application class to invoke private methods in any class with Infinispan's privileges. The attacker can use reflection to introduce new, malicious behavior into the application.
Use of Externally-Controlled Input to Select Classes or Code in Infinispan
Уязвимость метода открытого класса invokeAccessibly программного обеспечения для хранения данных Infinispan связана с применением входных данных с внешним управлением для выбора классов. Эксплуатация уязвимости может позволить нарушителю выполнить произвольный код
EPSS
7.5 High
CVSS3