Description
A flaw was found in infinispan 10 REST API, where authorization permissions are not checked while performing some server management operations. When authz is enabled, any user with authentication can perform operations like shutting down the server without the ADMIN role.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-0906 | A flaw was found in infinispan 10 REST API, where authorization permissions are not checked while performing some server management operations. When authz is enabled, any user with authentication can perform operations like shutting down the server without the ADMIN role. |
Github GHSA |
GHSA-8674-26jc-wh98 | Improper Access Control in infinispan-server-runtime |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-04T15:40:36.665Z
Reserved: 2020-09-16T00:00:00.000Z
Link: CVE-2020-25711
No data.
Status : Modified
Published: 2020-12-03T17:15:12.647
Modified: 2024-11-21T05:18:32.843
Link: CVE-2020-25711
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA