CVE-2020-10746: Medium severity infinispan infinispan-server-runtime vulnerability
A flaw was found in Infinispan (org.infinispan:infinispan-server-runtime) version 10, where it permits local access to controls via both REST and HotRod APIs. This flaw allows a user authenticated to the local machine to perform all operations on the caches, including the creation, update, deletion, and shutdown of the entire server.
Other sources
Infinispan permits local access to controls via both REST and HotRod APIs. A user authed to the local machine could perform all operations on the caches, including creation, update, deletion, and shutdown of the entire server.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-10746?
CVE-2020-10746 is a vulnerability found in Infinispan version 10 that allows local access to controls via REST and HotRod APIs.
What is the severity of CVE-2020-10746?
The severity of CVE-2020-10746 is high, with a CVSS score of 6.1.
How can the vulnerability CVE-2020-10746 be exploited?
The vulnerability CVE-2020-10746 can be exploited by a user authenticated to the local machine to perform all operations on the caches, including creation, update, and deletion.
Which software versions are affected by CVE-2020-10746?
CVE-2020-10746 affects Infinispan version 10.0.0 and below.
How can CVE-2020-10746 be fixed?
To fix CVE-2020-10746, it is recommended to upgrade to Infinispan version 11.0.0 or above.