6.5
CVE-2023-3628
- EPSS 0.64%
- Veröffentlicht 18.12.2023 14:15:08
- Zuletzt bearbeitet 21.11.2024 08:17:42
- Erkennungen
Infispan: rest bulk ops don't check permissions
A flaw was found in Infinispan's REST. Bulk read endpoints do not properly evaluate user permissions for the operation. This issue could allow an authenticated user to access information outside of their intended permissions.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Redhat ≫ Jboss Data Grid Version - SwEdition text-only
Redhat ≫ Jboss Enterprise Application Platform Version 6
Infinispan ≫ Infinispan Version -
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.64% | 0.458 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
| RedHat | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
CWE-304 Missing Critical Step in Authentication
The product implements an authentication technique, but it skips a step that weakens the technique.
https://access.redhat.com/errata/RHSA-2023:5396
https://access.redhat.com/security/cve/CVE-2023-3628
https://bugzilla.redhat.com/show_bug.cgi?id=2217924
https://security.netapp.com/advisory/ntap-20240125-0004/