CVE-2020-25711: Medium severity infinispan vulnerability
A flaw was found in infinispan 10 REST API, where authorization permissions are not checked while performing some server management operations. When authz is enabled, any user with authentication can perform operations like shutting down the server without the ADMIN role.
Other sources
A flaw was found in the Infinispan 10 REST API, where authorization permissions are not checked while performing some server management operations. When authz is enabled, any user with authentication can perform operations like shutting down the server without the ADMIN role. The highest threat from this vulnerability is to integrity and system availability.
Some server management operations don't check authorization permissions so, when authz is enabled, any user with authentication can perform operations like shutting down the server without the ADMIN role.
The following ops are affected: server stop cluster stop server report cache ignore list manipulation
This vulnerability affects the org.infinispan:infinispan-server-runtime artifact for all versions up to 11.0.5.Final.
https://issues.redhat.com/browse/JDG-4194
— Red Hat
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2020-25711?
CVE-2020-25711 is a vulnerability found in Infinispan 10 REST API where authorization permissions are not checked during certain server management operations.
What is the severity of CVE-2020-25711?
The severity of CVE-2020-25711 is medium, with a CVSS score of 6.5.
How does CVE-2020-25711 affect Infinispan?
CVE-2020-25711 allows any authenticated user to perform certain server management operations, such as shutting down the server, without the ADMIN role.
How can I fix CVE-2020-25711?
To fix CVE-2020-25711, update to Infinispan version 11.0.6 or above.
Is there any additional information available for CVE-2020-25711?
Yes, you can find more information about CVE-2020-25711 in the references provided: [link1](https://issues.redhat.com/browse/JDG-4194), [link2](https://access.redhat.com/errata/RHSA-2021:0433), [link3](https://access.redhat.com/security/cve/cve-2020-25711)