Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-5236

Опубликовано: 27 сент. 2023
Источник: redhat
CVSS3: 4.4
EPSS Низкий

Описание

A flaw was found in Infinispan, which does not detect circular object references when unmarshalling. An authenticated attacker with sufficient permissions could insert a maliciously constructed object into the cache and use it to cause out of memory errors and achieve a denial of service.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Data Grid 8infinispan-serverAffected
Red Hat Data Grid 8.4.4FixedRHSA-2023:539628.09.2023

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-1047
https://bugzilla.redhat.com/show_bug.cgi?id=2240999infinispan: circular reference on marshalling leads to DoS

EPSS

Процентиль: 28%
0.001
Низкий

4.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.4
nvd
около 2 лет назад

A flaw was found in Infinispan, which does not detect circular object references when unmarshalling. An authenticated attacker with sufficient permissions could insert a maliciously constructed object into the cache and use it to cause out of memory errors and achieve a denial of service.

CVSS3: 6.5
github
около 2 лет назад

Infinispan circular object references causes out of memory errors

EPSS

Процентиль: 28%
0.001
Низкий

4.4 Medium

CVSS3