CVE-2023-3629
—CVSS 3.1
6.5 medium
EPSS
<1%p46
Published
()
Modified
Description
A flaw was found in Infinispan's REST, Cache retrieval endpoints do not properly evaluate the necessary admin permissions for the operation. This issue could allow an authenticated user to access information outside of their intended permissions.
- Vendors
- redhatinfinispan
- Products
- data grid, jboss data grid, jboss enterprise application platform, infinispan
- Weakness
- CWE-304
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.