ZeroHour

CVE-2023-3629

CVSS 3.1
6.5 medium
EPSS
<1%p46
Published
()
Modified
Description

A flaw was found in Infinispan's REST, Cache retrieval endpoints do not properly evaluate the necessary admin permissions for the operation. This issue could allow an authenticated user to access information outside of their intended permissions.

Vendors
redhatinfinispan
Products
data grid, jboss data grid, jboss enterprise application platform, infinispan
Weakness
CWE-304
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.