Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: GSA_kwCzR0hTQS1maHI3LThqeDQtcjljcM4AA4G4

Infinispan REST Server's bulk read endpoints do not properly evaluate user permissions

A flaw was found in Infinispan's REST. Bulk read endpoints do not properly evaluate user permissions for the operation. This issue could allow an authenticated user to access information outside of their intended permissions.

Permalink: https://github.com/advisories/GHSA-fhr7-8jx4-r9cp
JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1maHI3LThqeDQtcjljcM4AA4G4
Source: GitHub Advisory Database
Origin: Unspecified
Severity: High
Classification: General
Published: 11 months ago
Updated: 14 days ago


CVSS Score: 6.5
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Identifiers: GHSA-fhr7-8jx4-r9cp, CVE-2023-3628
References: Repository: https://github.com/infinispan/infinispan
Blast Radius: 10.3

Affected Packages

maven:org.infinispan:infinispan-server-rest
Dependent packages: 59
Dependent repositories: 39
Downloads:
Affected Version Ranges: < 14.0.18.Final, >= 15.0.0.Dev01, < 15.0.0.Dev04
Fixed in: 14.0.18.Final, 15.0.0.Dev04
All affected versions: 14.0.1-0.Final, 14.0.1-1.Final, 14.0.1-2.Final, 14.0.1-3.Final, 14.0.1-4.Final, 14.0.1-5.Final, 14.0.1-6.Final, 14.0.1-7.Final
All unaffected versions: