Description
It was found that the Hotrod client in Infinispan before 9.2.0.CR1 would unsafely read deserialized data on information from the cache. An authenticated attacker could inject a malicious object into the data cache and attain deserialization on the client, and possibly conduct further attacks.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-2317 | It was found that the Hotrod client in Infinispan before 9.2.0.CR1 would unsafely read deserialized data on information from the cache. An authenticated attacker could inject a malicious object into the data cache and attain deserialization on the client, and possibly conduct further attacks. |
Github GHSA |
GHSA-46r5-59fg-2fjc | Deserialization of Untrusted Data in Infinispan |
References
History
Fri, 23 Aug 2024 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:jboss_enterprise_application_platform:7.1::el7 |
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-09-16T19:05:25.998Z
Reserved: 2017-10-08T00:00:00.000Z
Link: CVE-2017-15089
No data.
Status : Modified
Published: 2018-02-15T17:29:00.207
Modified: 2024-11-21T03:14:02.923
Link: CVE-2017-15089
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA