QID 994823

Date Published: 2023-08-14

QID 994823: Java (Maven) Security Update for org.infinispan:infinispan-server-core (GHSA-mvxp-3j62-jqr6)

It was found that the REST API in Infinispan before version 9.0.0 did not properly enforce auth constraints. An attacker could use this vulnerability to read or modify data in the default cache or a known cache name.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as High - 6.5 severity.
  • CVSS V2 rated as High - 6.4 severity.
  • Solution
    Refer to Github security advisory GHSA-mvxp-3j62-jqr6 for updates and patch information.
    Vendor References

    CVEs related to QID 994823

    Software Advisories
    Advisory ID Software Component Link
    GHSA-mvxp-3j62-jqr6 org.infinispan:infinispan-server-core URL Logo github.com/advisories/GHSA-mvxp-3j62-jqr6