A flaw was found in infinispan 10 REST API, where authorization permissions are not checked while performing some server management operations. When authz is enabled, any user with authentication can perform operations like shutting down the server without the ADMIN role.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-0906 | A flaw was found in infinispan 10 REST API, where authorization permissions are not checked while performing some server management operations. When authz is enabled, any user with authentication can perform operations like shutting down the server without the ADMIN role. |
Github GHSA |
GHSA-8674-26jc-wh98 | Improper Access Control in infinispan-server-runtime |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-04T15:40:36.665Z
Reserved: 2020-09-16T00:00:00
Link: CVE-2020-25711
No data.
Status : Modified
Published: 2020-12-03T17:15:12.647
Modified: 2024-11-21T05:18:32.843
Link: CVE-2020-25711
OpenCVE Enrichment
No data.
EUVD
Github GHSA