VulnerabilityModified
CVE-2017-2638
An attacker could use this vulnerability to read or modify data in the default cache or a known cache name.
MEDIUM 6.5EPSS 1.56%
Does this matter?
Lower severity and a low EPSS score (1.56%). Track it; it rarely justifies an emergency change on its own.
Description
It was found that the REST API in Infinispan before version 9.0.0 did not properly enforce auth constraints. An attacker could use this vulnerability to read or modify data in the default cache or a known cache name.
- CVSS 3.0
- 6.5 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
- EPSS
- 1.56% probability · 74th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-306, CWE-287
- Affected
- infinispan/infinispan · redhat/jboss data grid
- Source
- secalert@redhat.com
References
- http://rhn.redhat.com/errata/RHSA-2017-1097.htmlThird Party Advisory
- http://www.securityfocus.com/bid/97964Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2638Issue Tracking, Patch, Third Party Advisory
- https://github.com/infinispan/infinispan/pull/4936/commitsPatch, Third Party Advisory
- https://issues.jboss.org/browse/ISPN-7485Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2017-1097.htmlThird Party Advisory
- http://www.securityfocus.com/bid/97964Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2638Issue Tracking, Patch, Third Party Advisory
- https://github.com/infinispan/infinispan/pull/4936/commitsPatch, Third Party Advisory
- https://issues.jboss.org/browse/ISPN-7485Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.