REDHAT-BUG-1714359: Medium severity infinispan Infinispan vulnerability
A vulnerability was found in Infinispan up to version 9.4.14.Final. An improper implementation of the session fixation protection in the Spring Session integration may result in an incorrect session handling
Referrences: https://issues.jboss.org/browse/ISPN-10224
Upstream Patch: https://github.com/infinispan/infinispan/pull/6960
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1714359?
The severity of REDHAT-BUG-1714359 is considered to be moderate due to improper session handling.
How do I fix REDHAT-BUG-1714359?
To fix REDHAT-BUG-1714359, upgrade Infinispan to a version later than 9.4.14.Final.
What versions of Infinispan are affected by REDHAT-BUG-1714359?
Infinispan versions up to and including 9.4.14.Final are affected by REDHAT-BUG-1714359.
What is the nature of the vulnerability described in REDHAT-BUG-1714359?
The vulnerability in REDHAT-BUG-1714359 involves improper implementation of session fixation protection.
Is REDHAT-BUG-1714359 related to Spring Session integration?
Yes, REDHAT-BUG-1714359 is related to an improper session handling in the Spring Session integration.