REDHAT-BUG-1955113: Red hat data grid vulnerability
A flaw was found in Red Hat DataGrid 8.x (8.0.0, 8.0.1, 8.1.0 and 8.1.1) and Infinispan (10.0.0 through 12.0.0) where an attacker can bypass authentication in a trivial manor on all REST endpoints when DIGEST is used as the authentication method (authentication mechanisms).
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1955113?
The severity of REDHAT-BUG-1955113 is classified as critical due to the ability for attackers to bypass authentication.
How do I fix REDHAT-BUG-1955113?
To fix REDHAT-BUG-1955113, update to the latest version of Red Hat DataGrid or Infinispan that addresses this vulnerability.
Which versions are affected by REDHAT-BUG-1955113?
REDHAT-BUG-1955113 affects Red Hat DataGrid versions 8.0.0 to 8.1.1 and Infinispan versions 10.0.0 to 12.0.0.
What authentication method is vulnerable in REDHAT-BUG-1955113?
The vulnerable authentication method in REDHAT-BUG-1955113 is the 'DIGEST' method used on REST endpoints.
Is a workaround available for REDHAT-BUG-1955113?
There is no official workaround for REDHAT-BUG-1955113; the recommended action is to apply the security updates.