Description
A flaw was found in infinispan 10 REST API, where authorization permissions are not checked while performing some server management operations. When authz is enabled, any user with authentication can perform operations like shutting down the server without the ADMIN role.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-0906 | A flaw was found in infinispan 10 REST API, where authorization permissions are not checked while performing some server management operations. When authz is enabled, any user with authentication can perform operations like shutting down the server without the ADMIN role. |
Github GHSA |
GHSA-8674-26jc-wh98 | Improper Access Control in infinispan-server-runtime |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-04T15:40:36.665Z
Reserved: 2020-09-16T00:00:00.000Z
Link: CVE-2020-25711
No data.
Status : Modified
Published: 2020-12-03T17:15:12.647
Modified: 2026-06-17T03:07:10.440
Link: CVE-2020-25711
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-862
Missing Authorization
EUVD
Github GHSA