First published: Thu May 14 2020(Updated: )
Infinispan permits local access to controls via both REST and HotRod APIs. A user authed to the local machine could perform all operations on the caches, including creation, update, deletion, and shutdown of the entire server.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/Infinispan | <11.0.0 | 11.0.0 |
Infinispan Infinispan-server-runtime | =10.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-10746 is a vulnerability found in Infinispan version 10 that allows local access to controls via REST and HotRod APIs.
The severity of CVE-2020-10746 is high, with a CVSS score of 6.1.
The vulnerability CVE-2020-10746 can be exploited by a user authenticated to the local machine to perform all operations on the caches, including creation, update, and deletion.
CVE-2020-10746 affects Infinispan version 10.0.0 and below.
To fix CVE-2020-10746, it is recommended to upgrade to Infinispan version 11.0.0 or above.