MidnightBSD

Advisories for infinispan

CVE-2016-0750 MEDIUM

The hotrod java client in infinispan before 9.1.0.Final automatically deserializes bytearray message contents in certain events. A malicious user could exploit this flaw by injecting a specially-crafted serialized object to attain remote code execution or conduct other attacks.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-138,CWE-502,

Products Affected

Vendor Product Version
infinispan infinispan *
CVE-2017-15089 MEDIUM

It was found that the Hotrod client in Infinispan before 9.2.0.CR1 would unsafely read deserialized data on information from the cache. An authenticated attacker could inject a malicious object into the data cache and attain deserialization on the client, and possibly conduct further attacks.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-502,CWE-502,

Products Affected

Vendor Product Version
infinispan infinispan *
infinispan infinispan 9.2.0
CVE-2017-2638 MEDIUM

It was found that the REST API in Infinispan before version 9.0.0 did not properly enforce auth constraints. An attacker could use this vulnerability to read or modify data in the default cache or a known cache name.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-306,CWE-287,

Products Affected

Vendor Product Version
redhat jboss_data_grid 7.1
infinispan infinispan *
CVE-2018-1131 MEDIUM

Infinispan permits improper deserialization of trusted data via XML and JSON transcoders under certain server configurations. A user with authenticated access to the server could send a malicious object to a cache configured to accept certain types of objects, achieving code execution and possible further attacks. Versions 9.0.3.Final, 9.1.7.Final, 8.2.10.Final, 9.2.2.Final, 9.3.0.Alpha1 are believed to be affected.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-349,CWE-502,

Products Affected

Vendor Product Version
redhat jboss_data_grid 7.2
infinispan infinispan 9.2.2
infinispan infinispan 9.0.3
infinispan infinispan 8.2.10
infinispan infinispan 9.3.0
infinispan infinispan 9.1.7