CVE-2018-1131: High severity infinispan Infinispan vulnerability
Infinispan permits improper deserialization of trusted data via XML and JSON transcoders under certain server configurations. A user with authenticated access to the server could send a malicious object to a cache configured to accept certain types of objects, achieving code execution and possible further attacks.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/Infinispanto a version that resolves this vulnerability.Fixed in 9.4.0. - Upgrade
Upgrade
redhat/Infinispanto a version that resolves this vulnerability.Fixed in 9.3.1. - Compensating control
Ensure the cache configuration does not accept/allow untrusted object types via XML and JSON transcoders to prevent improper deserialization that can lead to code execution (notably in the affected Infinispan versions: 9.0.3.Final, 9.1.7.Final, 8.2.10.Final, 9.2.2.Final, 9.3.0.Alpha1).
Event History
Frequently Asked Questions
What is CVE-2018-1131?
CVE-2018-1131 is a vulnerability in Infinispan that allows for improper deserialization of trusted data via XML and JSON transcoders under certain server configurations.
How does CVE-2018-1131 affect Infinispan?
CVE-2018-1131 affects Infinispan versions 8.2.10, 9.0.3, 9.1.7, 9.2.2, and 9.3.0-alpha1, as well as versions 9.3.1 and 9.4.0.
What is the severity of CVE-2018-1131?
CVE-2018-1131 has a severity rating of 8.8, which is considered high.
How can I fix CVE-2018-1131 in Infinispan?
To fix CVE-2018-1131 in Infinispan, update to version 9.3.1 or 9.4.0.
Where can I find more information about CVE-2018-1131?
You can find more information about CVE-2018-1131 on the Red Hat website and Bugzilla.