Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: GSA_kwCzR0hTQS1oNDd4LTJqMzctZnc1bc4AAiwa

Use of Externally-Controlled Input to Select Classes or Code in Infinispan

A vulnerability was found in Infinispan such that the invokeAccessibly method from the public class ReflectionUtil allows any application class to invoke private methods in any class with Infinispan's privileges. The attacker can use reflection to introduce new, malicious behavior into the application.

Permalink: https://github.com/advisories/GHSA-h47x-2j37-fw5m
JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1oNDd4LTJqMzctZnc1bc4AAiwa
Source: GitHub Advisory Database
Origin: Unspecified
Severity: High
Classification: General
Published: over 2 years ago
Updated: almost 2 years ago


CVSS Score: 7.5
CVSS vector: CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Identifiers: GHSA-h47x-2j37-fw5m, CVE-2019-10174
References: Repository: https://github.com/infinispan/infinispan
Blast Radius: 27.1

Affected Packages

maven:org.infinispan:infinispan-core
Dependent packages: 543
Dependent repositories: 4,067
Downloads:
Affected Version Ranges: >= 9.0.0.Final, <= 9.4.16.Final, <= 8.2.11.Final
Fixed in: 9.4.17.Final, 8.2.12.Final
All affected versions: 8.2.1-0.Final, 8.2.1-1.Final, 9.4.1-0.Final, 9.4.1-1.Final, 9.4.1-2.Final, 9.4.1-3.Final, 9.4.1-4.Final, 9.4.1-5.Final, 9.4.1-6.Final
All unaffected versions: