PT-2018-7153 · Red Hat · Infinispan
Tristan Tarrant
·
Published
2018-07-16
·
Updated
2022-05-13
·
CVE-2017-2638
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
Infinispan versions prior to 9.0.0
Description:
The issue concerns the REST API in Infinispan, where auth constraints are not properly enforced. This allows an attacker to potentially read or modify data in the default cache or a known cache name.
Recommendations:
For versions prior to 9.0.0, update to version 9.0.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the REST API to minimize the risk of exploitation.
Fix
Missing Authentication
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Infinispan