First published: Fri Nov 13 2020(Updated: )
A flaw was found in infinispan 10 REST API, where authorization permissions are not checked while performing some server management operations. When authz is enabled, any user with authentication can perform operations like shutting down the server without the ADMIN role.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/Infinispan | <11.0.6 | 11.0.6 |
Infinispan Infinispan | <11.0.6 | |
Redhat Data Grid | =8.0 | |
Netapp Active Iq Unified Manager Linux | ||
Netapp Active Iq Unified Manager Vmware Vsphere | ||
Netapp Active Iq Unified Manager Windows |
There is currently no known mitigation for this issue.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-25711 is a vulnerability found in Infinispan 10 REST API where authorization permissions are not checked during certain server management operations.
The severity of CVE-2020-25711 is medium, with a CVSS score of 6.5.
CVE-2020-25711 allows any authenticated user to perform certain server management operations, such as shutting down the server, without the ADMIN role.
To fix CVE-2020-25711, update to Infinispan version 11.0.6 or above.
Yes, you can find more information about CVE-2020-25711 in the references provided: [link1](https://issues.redhat.com/browse/JDG-4194), [link2](https://access.redhat.com/errata/RHSA-2021:0433), [link3](https://access.redhat.com/security/cve/cve-2020-25711)