ZeroHour

CVE-2023-3628

CVSS 3.1
6.5 medium
EPSS
<1%p49
Published
()
Modified
Description

A flaw was found in Infinispan's REST. Bulk read endpoints do not properly evaluate user permissions for the operation. This issue could allow an authenticated user to access information outside of their intended permissions.

Vendors
redhatinfinispan
Products
jboss data grid, jboss enterprise application platform, data grid, infinispan
Weakness
CWE-304
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.