Infinispan Rest API Does Not Enforce Auth Constraints
Moderate severity
GitHub Reviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Jul 31, 2023
Package
Affected versions
< 9.0.0
Patched versions
9.0.0
Description
Published by the National Vulnerability Database
Jul 16, 2018
Published to the GitHub Advisory Database
May 13, 2022
Reviewed
Jul 31, 2023
Last updated
Jul 31, 2023
It was found that the REST API in Infinispan before version 9.0.0 did not properly enforce auth constraints. An attacker could use this vulnerability to read or modify data in the default cache or a known cache name.
References