Описание
A flaw was found in Infinispan, which does not detect circular object references when unmarshalling. An authenticated attacker with sufficient permissions could insert a maliciously constructed object into the cache and use it to cause out of memory errors and achieve a denial of service.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat build of Apache Camel 4 for Quarkus 3 | protostream | Fix deferred | ||
| Red Hat build of Apache Camel 4 for Quarkus 3 | protostream-processor | Fix deferred | ||
| Red Hat build of Apache Camel 4 for Quarkus 3 | protostream-types | Fix deferred | ||
| Red Hat build of Apache Camel for Spring Boot 4 | protostream | Fix deferred | ||
| Red Hat build of Apache Camel for Spring Boot 4 | protostream-processor | Fix deferred | ||
| Red Hat build of Apache Camel for Spring Boot 4 | protostream-types | Fix deferred | ||
| Red Hat build of Debezium 2 | protostream | Fix deferred | ||
| Red Hat build of Debezium 2 | protostream-processor | Fix deferred | ||
| Red Hat build of Debezium 2 | protostream-types | Fix deferred | ||
| Red Hat build of Debezium 3 | protostream | Fix deferred |
Показывать по
10
Дополнительная информация
Статус:
Low
https://bugzilla.redhat.com/show_bug.cgi?id=2240999infinispan: circular reference on marshalling leads to DoS
4.4 Medium
CVSS3
Связанные уязвимости
CVSS3: 4.4
nvd
больше 2 лет назад
A flaw was found in Infinispan, which does not detect circular object references when unmarshalling. An authenticated attacker with sufficient permissions could insert a maliciously constructed object into the cache and use it to cause out of memory errors and achieve a denial of service.
CVSS3: 6.5
github
больше 2 лет назад
Infinispan circular object references causes out of memory errors
4.4 Medium
CVSS3