MEDIUM6.5
GHSA-r4w2-hjmr-36m7
Infinispan REST Server's cache retrieval endpoints do not properly evaluate the necessary admin permissions
Quick fix
GHSA-r4w2-hjmr-36m7 — org.infinispan:infinispan-server-rest: upgrade to the fixed version with the command below.
# pom.xml: bump <version>15.0.0.Dev04</version> for org.infinispan:infinispan-server-restDetails
A flaw was found in Infinispan's REST, Cache retrieval endpoints do not properly evaluate the necessary admin permissions for the operation. This issue could allow an authenticated user to access information outside of their intended permissions.
Are you affected?
Enter the version of the package you're using.
Affected packages
Maven/org.infinispan:infinispan-server-rest
Introduced in:
15.0.0.Dev01Fixed in: 15.0.0.Dev04Fix
# pom.xml: bump <version>15.0.0.Dev04</version> for org.infinispan:infinispan-server-restMaven/org.infinispan:infinispan-server-rest
Introduced in:
0Fixed in: 14.0.18.FinalFix
# pom.xml: bump <version>14.0.18.Final</version> for org.infinispan:infinispan-server-restReferences
- https://nvd.nist.gov/vuln/detail/CVE-2023-3629[ADVISORY]
- https://github.com/infinispan/infinispan/commit/11b3cb0f7ba68b73dd32f655ff3f3df842a0c6bd[WEB]
- https://github.com/infinispan/infinispan/commit/1e3cc542336d2f49743ab8176ed6f1175e034c59[WEB]
- https://access.redhat.com/errata/RHSA-2023:5396[WEB]
- https://access.redhat.com/security/cve/CVE-2023-3629[WEB]
- https://bugzilla.redhat.com/show_bug.cgi?id=2217926[WEB]
- https://github.com/infinispan/infinispan[PACKAGE]
- https://security.netapp.com/advisory/ntap-20240125-0004[WEB]