MEDIUM6.5
GHSA-fhr7-8jx4-r9cp
Infinispan REST Server's bulk read endpoints do not properly evaluate user permissions
Quick fix
GHSA-fhr7-8jx4-r9cp — org.infinispan:infinispan-server-rest: upgrade to the fixed version with the command below.
# pom.xml: bump <version>15.0.0.Dev04</version> for org.infinispan:infinispan-server-restDetails
A flaw was found in Infinispan's REST. Bulk read endpoints do not properly evaluate user permissions for the operation. This issue could allow an authenticated user to access information outside of their intended permissions.
Are you affected?
Enter the version of the package you're using.
Affected packages
Maven/org.infinispan:infinispan-server-rest
Introduced in:
15.0.0.Dev01Fixed in: 15.0.0.Dev04Fix
# pom.xml: bump <version>15.0.0.Dev04</version> for org.infinispan:infinispan-server-restMaven/org.infinispan:infinispan-server-rest
Introduced in:
0Fixed in: 14.0.18.FinalFix
# pom.xml: bump <version>14.0.18.Final</version> for org.infinispan:infinispan-server-restReferences
- https://nvd.nist.gov/vuln/detail/CVE-2023-3628[ADVISORY]
- https://github.com/infinispan/infinispan/commit/70a50352d9195753a588d0fba8c2063b99f96263[WEB]
- https://github.com/infinispan/infinispan/commit/b34488dcab8bdd4258972568b8405ee7111276ec[WEB]
- https://access.redhat.com/errata/RHSA-2023:5396[WEB]
- https://access.redhat.com/security/cve/CVE-2023-3628[WEB]
- https://bugzilla.redhat.com/show_bug.cgi?id=2217924[WEB]
- https://github.com/infinispan/infinispan[PACKAGE]
- https://security.netapp.com/advisory/ntap-20240125-0004[WEB]