PT-2018-7153 · Red Hat · Infinispan
Tristan Tarrant
·
Publicado
2018-07-16
·
Atualizado
2022-05-13
·
CVE-2017-2638
CVSS v3.1
6.5
Média
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
Infinispan versions prior to 9.0.0
Description:
The issue concerns the REST API in Infinispan, where auth constraints are not properly enforced. This allows an attacker to potentially read or modify data in the default cache or a known cache name.
Recommendations:
For versions prior to 9.0.0, update to version 9.0.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the REST API to minimize the risk of exploitation.
Correção
Missing Authentication
Improper Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Infinispan