VulnerabilityModified
CVE-2023-3628
This issue could allow an authenticated user to access information outside of their intended permissions.
MEDIUM 6.5EPSS 0.64%
Does this matter?
Lower severity and a low EPSS score (0.64%). Track it; it rarely justifies an emergency change on its own.
Description
A flaw was found in Infinispan's REST. Bulk read endpoints do not properly evaluate user permissions for the operation. This issue could allow an authenticated user to access information outside of their intended permissions.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.64% probability · 49th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-304
- Affected
- redhat/jboss data grid · redhat/jboss enterprise application platform · redhat/data grid · infinispan/infinispan
- Source
- secalert@redhat.com
References
- https://access.redhat.com/errata/RHSA-2023:5396Vendor Advisory
- https://access.redhat.com/security/cve/CVE-2023-3628Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2217924Issue Tracking
- https://access.redhat.com/errata/RHSA-2023:5396Vendor Advisory
- https://access.redhat.com/security/cve/CVE-2023-3628Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2217924Issue Tracking
- https://security.netapp.com/advisory/ntap-20240125-0004/
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.