First published: Wed Sep 27 2023(Updated: )
A flaw was found in Infinispan, which does not detect circular object references when unmarshalling. An authenticated attacker with sufficient permissions could insert a maliciously constructed object into the cache and use it to cause out of memory errors and achieve a denial of service.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Data Grid | <8.4.4 | |
Redhat Jboss Data Grid | ||
Infinispan Infinispan | ||
maven/org.infinispan.protostream:protostream | <4.6.2.Final | 4.6.2.Final |
<8.4.4 | ||
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.