CVE-2017-15089: High severity infinispan Infinispan vulnerability
A vulnerability in Infinispan was found allowing malicious users to inject malicious serialized objects into server's data cache and potentially execute arbitrary code on other user's machine when the malicious data are fetched using hotrod protocol.
Other sources
It was found that the Hotrod client in Infinispan before 9.2.0.CR1 would unsafely read deserialized data on information from the cache. An authenticated attacker could inject a malicious object into the data cache and attain deserialization on the client, and possibly conduct further attacks.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/Infinispanto a version that resolves this vulnerability.Fixed in 8.2.9. - Upgrade
Upgrade
redhat/Infinispanto a version that resolves this vulnerability.Fixed in 9.2.0.
Event History
Frequently Asked Questions
What is the severity of CVE-2017-15089?
CVE-2017-15089 is considered a moderate severity vulnerability due to its potential for deserialization attacks.
How do I fix CVE-2017-15089?
To fix CVE-2017-15089, upgrade Infinispan to version 9.2.0.CR1 or later.
What types of attacks can be conducted due to CVE-2017-15089?
An authenticated attacker could exploit CVE-2017-15089 to inject malicious objects into the data cache, enabling further attacks.
Who is affected by CVE-2017-15089?
CVE-2017-15089 affects versions of Infinispan prior to 9.2.0.CR1 and specific alpha and beta versions.
What is the impact of CVE-2017-15089 on Infinispan?
The impact of CVE-2017-15089 is the possibility of unauthorized access and manipulation of cached data through unsafe deserialization.