Описание
A flaw was found in Infinispan version 10, where it is possible to perform various actions that could have side effects using GET requests. This flaw allows an attacker to perform a cross-site request forgery (CSRF) attack.
A flaw was found in infinispan-server-rest version 10, where it is possible to perform various actions that could have side effects using GET requests. This flaw allows an attacker to perform a Cross-site request forgery (CSRF) attack.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Fuse 7 | infinispan-rest | Not affected | ||
| Red Hat JBoss Data Grid 7 | infinispan-rest | Not affected | ||
| Red Hat JBoss Data Virtualization 6 | infinispan-rest | Not affected | ||
| Red Hat JBoss Enterprise Application Platform 6 | infinispan-rest | Not affected | ||
| Red Hat JBoss Fuse Service Works 6 | infinispan-rest | Not affected | ||
| Red Hat Data Grid 8.2.0 | infinispan-server-rest | Fixed | RHSA-2021:2139 | 26.05.2021 |
Показывать по
Дополнительная информация
Статус:
EPSS
7.1 High
CVSS3
Связанные уязвимости
A flaw was found in Infinispan version 10, where it is possible to perform various actions that could have side effects using GET requests. This flaw allows an attacker to perform a cross-site request forgery (CSRF) attack.
A flaw was found in Infinispan version 10, where it is possible to perform various actions that could have side effects using GET requests. This flaw allows an attacker to perform a cross-site request forgery (CSRF) attack.
EPSS
7.1 High
CVSS3