Description
It was found that the REST API in Infinispan before version 9.0.0 did not properly enforce auth constraints. An attacker could use this vulnerability to read or modify data in the default cache or a known cache name.
Remediation
References
http://rhn.redhat.com/errata/RHSA-2017-1097.html
http://www.securityfocus.com/bid/97964
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2638
https://github.com/infinispan/infinispan/pull/4936/commits
https://issues.jboss.org/browse/ISPN-7485
Related Vulnerabilities
CVE-2020-22864 Vulnerability in npm package froala-editor
CVE-2023-40989 Vulnerability in maven package org.jeecgframework.boot:jeecg-boot-common
CVE-2020-15366 Vulnerability in maven package org.webjars.bowergithub.ajv-validator:ajv
CVE-2018-7408 Vulnerability in maven package org.webjars.bower:npm
CVE-2016-6816 Vulnerability in maven package org.apache.tomcat:coyote