CVE-2017-2638: Medium severity infinispan vulnerability
It was found that the REST API in Infinispan before version 9.0.0 did not properly enforce auth constraints. An attacker could use this vulnerability to read or modify data in the default cache or a known cache name.
Other sources
JDG REST API does not enforce auth constraints.
Doc text: It was found that the REST API in infinispan did not properly enforce auth constraints. An attacker could use this vulnerability to read or modify data in the default cache or a known cache name.
— Red Hat
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-2638?
The severity of CVE-2017-2638 is classified as medium, as it allows unauthorized access to sensitive data.
How do I fix CVE-2017-2638?
To fix CVE-2017-2638, upgrade to Infinispan version 9.0.0 or later.
What systems are affected by CVE-2017-2638?
CVE-2017-2638 affects Infinispan versions prior to 9.0.0 and Red Hat JBoss Data Grid version 7.1.
What is the impact of CVE-2017-2638?
The impact of CVE-2017-2638 is that an attacker could read or modify data in the default cache without authentication.
Is authentication enforced in CVE-2017-2638?
No, authentication is not properly enforced in the REST API of Infinispan prior to version 9.0.0.