Description
A flaw was found in infinispan 10 REST API, where authorization permissions are not checked while performing some server management operations. When authz is enabled, any user with authentication can perform operations like shutting down the server without the ADMIN role.
Remediation
References
https://bugzilla.redhat.com/show_bug.cgi?id=1897618
https://security.netapp.com/advisory/ntap-20220210-0023/
Related Vulnerabilities
CVE-2019-1003058 Vulnerability in maven package org.jvnet.hudson.plugins:ftppublisher
CVE-2019-1003053 Vulnerability in maven package org.jenkins-ci.plugins:hockeyapp
CVE-2023-31582 Vulnerability in maven package org.bitbucket.b_c:jose4j
CVE-2021-23326 Vulnerability in npm package @graphql-tools/git-loader
CVE-2023-3414 Vulnerability in maven package io.jenkins.plugins:servicenow-devops