Description
It was found that the REST API in Infinispan before version 9.0.0 did not properly enforce auth constraints. An attacker could use this vulnerability to read or modify data in the default cache or a known cache name.
Remediation
References
https://issues.jboss.org/browse/ISPN-7485
https://github.com/infinispan/infinispan/pull/4936/commits
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2638
http://www.securityfocus.com/bid/97964
http://rhn.redhat.com/errata/RHSA-2017-1097.html
Related Vulnerabilities
CVE-2023-40813 Vulnerability in maven package org.opencrx:opencrx-core-models
CVE-2019-17495 Vulnerability in maven package org.webjars.bower:swagger-ui
CVE-2022-39322 Vulnerability in npm package @keystone-6/core
CVE-2019-16776 Vulnerability in maven package org.webjars:npm
CVE-2019-10746 Vulnerability in maven package org.webjars.npm:mixin-deep