It was found that the REST API in Infinispan before version 9.0.0 did not properly enforce auth constraints. An attacker could use this vulnerability to read or modify data in the default cache or a known cache name.
References
Link | Resource |
---|---|
https://issues.jboss.org/browse/ISPN-7485 | Third Party Advisory |
https://github.com/infinispan/infinispan/pull/4936/commits | Patch Third Party Advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2638 | Issue Tracking Patch Third Party Advisory |
http://www.securityfocus.com/bid/97964 | Third Party Advisory VDB Entry |
http://rhn.redhat.com/errata/RHSA-2017-1097.html | Third Party Advisory |
Information
Published : 2018-07-16 06:29
Updated : 2019-10-09 16:27
NVD link : CVE-2017-2638
Mitre link : CVE-2017-2638
JSON object : View
CWE
CWE-287
Improper Authentication
Products Affected
infinispan
- infinispan
redhat
- jboss_data_grid