
We found results for “”
CVE-2020-25711
Good to know:

Date: December 2, 2020
A flaw was found in infinispan 10 REST API, where authorization permissions are not checked while performing some server management operations. When authz is enabled, any user with authentication can perform operations like shutting down the server without the ADMIN role.
Language: Java
Severity Score
Severity Score
Top Fix

Upgrade Version
Upgrade to version org.infinispan:infinispan-server-runtime:11.0.6.Final;org.infinispan:infinispan-server-runtime:10.1.9.Final;org.infinispan:infinispan-server-runtime:11.0.6.Final;org.infinispan:infinispan-server-runtime:10.1.9.Final
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | HIGH |
User Interaction (UI): | NONE |
Scope (S): | UNCHANGED |
Confidentiality (C): | NONE |
Integrity (I): | HIGH |
Availability (A): | HIGH |
CVSS v2
Base Score: |
|
---|---|
Access Vector (AV): | NETWORK |
Access Complexity (AC): | MEDIUM |
Authentication (AU): | SINGLE |
Confidentiality (C): | NONE |
Integrity (I): | PARTIAL |
Availability (A): | PARTIAL |
Additional information: |