PT-2018-4626 · Red Hat · Infinispan
Chess Hazlett
+1
·
Published
2018-09-11
·
Updated
2021-04-07
·
CVE-2016-0750
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Infinispan versions prior to 9.1.0.Final
Description
The issue allows a malicious user to inject a specially-crafted serialized object, potentially leading to remote code execution or other attacks, due to the automatic deserialization of bytearray message contents in certain events by the hotrod java client.
Recommendations
For versions prior to 9.1.0.Final, update to version 9.1.0.Final or later to resolve the issue. As a temporary workaround, consider restricting access to the hotrod java client to minimize the risk of exploitation.
Fix
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Infinispan