First published: Thu Jun 04 2020(Updated: )
A flaw was found in Infinispan version 10, where it is possible to perform various actions that could have side effects using GET requests. This flaw allows an attacker to perform a cross-site request forgery (CSRF) attack.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Infinispan Infinispan-server-rest | =10.0.0 | |
Redhat Data Grid | =8.0 | |
NetApp OnCommand Insight |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this security flaw is CVE-2020-10771.
CVE-2020-10771 has a severity level of high.
CVE-2020-10771 is a flaw in infinispan-server-rest version 10 that allows an attacker to perform a Cross-site request forgery (CSRF) attack.
The affected software version for CVE-2020-10771 is infinispan-server-rest version 10.
To fix CVE-2020-10771, you should upgrade to a version of infinispan-server-rest that has addressed the vulnerability.