First published: Thu Apr 29 2021(Updated: )
A flaw was found in Red Hat DataGrid 8.x (8.0.0, 8.0.1, 8.1.0 and 8.1.1) and Infinispan (10.0.0 through 12.0.0) where an attacker can bypass authentication in a trivial manor on all REST endpoints when `DIGEST` is used as the authentication method (`authentication mechanisms`).
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Infinispan infinispan-server-rest | >=10.0.0<11.0.12 | |
Infinispan infinispan-server-rest | >=12.0.0<12.1.4 | |
Red Hat Data Grid | =8.0.0 | |
Red Hat Data Grid | =8.0.1 | |
Red Hat Data Grid | =8.1.0 | |
Red Hat Data Grid | =8.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-31917 is a vulnerability found in Red Hat DataGrid 8.x and Infinispan 10.0.0 through 12.0.0 that allows an attacker to bypass authentication on all REST endpoints when DIGEST is used as the authentication method.
The severity of CVE-2021-31917 is critical with a CVSS score of 9.8.
CVE-2021-31917 poses a high threat to data confidentiality.
Red Hat DataGrid versions 8.0.0, 8.0.1, 8.1.0, and 8.1.1, as well as Infinispan versions 10.0.0 through 12.0.0, are affected by CVE-2021-31917.
To fix CVE-2021-31917, it is recommended to update to the latest versions of Red Hat DataGrid and Infinispan.