First published: Wed Sep 27 2023(Updated: )
A flaw was found in Infinispan, which does not detect circular object references when unmarshalling. An authenticated attacker with sufficient permissions could insert a maliciously constructed object into the cache and use it to cause out of memory errors and achieve a denial of service.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
maven/org.infinispan.protostream:protostream | <4.6.2.Final | 4.6.2.Final |
Red Hat Data Grid | <8.4.4 | |
redhat jboss data grid | ||
Infinispan |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-5236 has been classified as a moderate severity vulnerability.
To fix CVE-2023-5236, it is recommended to upgrade to Infinispan version 4.6.2.Final or higher.
CVE-2023-5236 affects Infinispan, Red Hat Data Grid, and JBoss Data Grid software.
Yes, CVE-2023-5236 can lead to denial of service by causing out of memory errors.
An authenticated attacker with sufficient permissions can exploit CVE-2023-5236 to insert a maliciously constructed object.