CVE-2020-25711 – org.infinispan:infinispan-core
Package
Manager: maven
Name: org.infinispan:infinispan-core
Vulnerable Version: >=0 <11.0.6.final
Severity
Level: Medium
CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS: 0.00183 pctl0.40246
Details
Improper Access Control in infinispan-server-runtime A flaw was found in infinispan 10 REST API, where authorization permissions are not checked while performing some server management operations. When authz is enabled, any user with authentication can perform operations like shutting down the server without the ADMIN role.
Metadata
Created: 2022-02-09T22:56:32Z
Modified: 2022-02-09T22:56:32Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/02/GHSA-8674-26jc-wh98/GHSA-8674-26jc-wh98.json
CWE IDs: ["CWE-269", "CWE-862"]
Alternative ID: GHSA-8674-26jc-wh98
Finding: F039
Auto approve: 1