Where
-Infinity
0
Severity
6.5
AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

A vulnerability was found in the Infinispan component in Red Hat Data Grid. The REST compare API may have a buffer leak and an out of memory error can occur when sending continual requests with large POST data to the REST API.

1 / 2
Source: GitHub
First published (updated )
Severity
7.2
EPSS
0.12%
AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

A flaw was found in Infinispan. When serializing the configuration for a cache to XML/JSON/YAML, which contains credentials (JDBC store with connection pooling, remote store), the credentials are returned in clear text as part of the configuration.

1 / 2
Source: GitHub
First published (updated )
Severity
7.4
Input Validation
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Withdrawn Advisory This advisory has been withdrawn because the underlying vulnerability only concerns Red Hat's Hot Rod client, which is not in one of the GitHub Advisory Database's supported ecosystems. This link is maintained to preserve external references.

Original Description Netty-handler has been found to no validate hostnames when using TLS in its default configuration. As a result netty-handler is vulnerable to man-in-the-middle attacks. Users would need to set the protocol to "HTTPS" in the SSLParameters of the SSLEngine to opt in to host name validation. A change in default behavior is expected in the 5.x release branch with no backport planned.

In the interim users are advised to enable host name validation in their configurations. See https://github.com/netty/netty/issues/8537 for details on the forthcoming change in default behavior.

1 / 3
First published (updated )

Red Hat Data Grid is an in-memory, distributed, NoSQL datastore solution. It increases application response times and allows for dramatically improving performance while providing availability, reliability, and elastic scale.Data Grid 8.3.1 replaces Data Grid 8.3.0 and includes bug fixes and enhancements. Find out more about Data Grid 8.3.1 in the Release Notes[3].Security Fix(es): jackson-databind: denial of service via a large depth of nested objects [jdg-8] (CVE-2020-36518) kafka-clients: Kafka: Timing Attack Vulnerability for Apache Kafka Connect and Clients [jdg-8] (CVE-2021-38153) xnio: org.xnio.StreamConnection.notifyReadClosed log to debug instead of stderr [jdg-8] (CVE-2022-0084) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Remedy

To install this update, do the following:<br>1. Download the Data Grid 8.3.1 Server patch from the customer portal[²].<br>2. Back up your existing Data Grid installation. You should back up databases, configuration files, and so on.<br>3. Install the Data Grid 8.3.1 Server patch.<br>4. Restart Data Grid to ensure the changes take effect.<br>For more information about Data Grid 8.3.1, refer to the 8.3.1 Release Notes[³]
First published (updated )
SQL Injection

Red Hat Data Grid is an in-memory, distributed, NoSQL datastore solution. It increases application response times and allows for dramatically improving performance while providing availability, reliability, and elastic scale.Data Grid 7.3.9 replaces Data Grid 7.3.8 and includes bug fixes and enhancements. Find out more about Data Grid 7.3.8 in the Release Notes [3].Security Fix(es): log4j: SQL injection in Log4j 1.x when application is configured to use JDBCAppender (CVE-2022-23305) log4j: Unsafe deserialization flaw in Chainsaw log viewer (CVE-2022-23307) log4j: Remote code execution in Log4j 1.x when application is configured to use JMSAppender (CVE-2021-4104) log4j: Remote code execution in Log4j 1.x when application is configured to use JMSSink (CVE-2022-23302) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Remedy

To install this update, do the following:<br>1. Download the Data Grid 7.3.9 server patch from the customer portal[²].<br>2. Back up your existing Data Grid installation. You should back up databases, configuration files, and so on.<br>3. Install the Data Grid 7.3.9 server patch. Refer to the 7.3.9 Release Notes[³] for patching instructions.<br>4. Restart Data Grid to ensure the changes take effect.
First published (updated )

A flaw was found in Red Hat DataGrid 8.x (8.0.0, 8.0.1, 8.1.0 and 8.1.1) and Infinispan (10.0.0 through 12.0.0) where an attacker can bypass authentication in a trivial manor on all REST endpoints when DIGEST is used as the authentication method (authentication mechanisms).

First published (updated )
Severity
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

A flaw was found in Red Hat DataGrid 8.x (8.0.0, 8.0.1, 8.1.0 and 8.1.1) and Infinispan (10.0.0 through 12.0.0) where an attacker can bypass authentication in a trivial manor on all REST endpoints when DIGEST is used as the authentication method (authentication mechanisms).

1 / 3
Source: Red Hat
First published (updated )
Severity
6.5
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H

A flaw was found in infinispan 10 REST API, where authorization permissions are not checked while performing some server management operations. When authz is enabled, any user with authentication can perform operations like shutting down the server without the ADMIN role.

1 / 3

Remedy

There is currently no known mitigation for this issue.
First published (updated )
Severity
7.5
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

A memory leak flaw was found in WildFly OpenSSL in versions prior to 1.1.3.Final, where it removes an HTTP session. It may allow the attacker to cause OOM leading to a denial of service. The highest threat from this vulnerability is to system availability.

1 / 3

Remedy

There is currently no known mitigation for this issue.
First published (updated )

Red Hat Data Grid is a distributed, in-memory, NoSQL datastore based on the Infinispan project.This release of Red Hat Data Grid 7.3.7 serves as a replacement for Red Hat Data Grid 7.3.6 and includes bug fixes and enhancements, which are described in the Release Notes, linked to in the References section of this erratum.Security Fix(es): jetty: Incorrect header handling (CVE-2017-7658) EAP: field-name is not parsed in accordance to RFC7230 (CVE-2020-1710) undertow: AJP File Read/Inclusion Vulnerability (CVE-2020-1745) undertow: servletPath is normalized incorrectly leading to dangerous application mapping which could result in security bypass (CVE-2020-1757) jackson-databind: Lacks certain xbean-reflect/JNDI blocking (CVE-2020-8840) jackson-databind: Serialization gadgets in shaded-hikari-config (CVE-2020-9546) jackson-databind: Serialization gadgets in ibatis-sqlmap (CVE-2020-9547) jackson-databind: Serialization gadgets in anteros-core (CVE-2020-9548) jackson-databind: mishandles the interaction between serialization gadgets and typing which could result in remote command execution (CVE-2020-10672) jackson-databind: mishandles the interaction between serialization gadgets and typing which could result in remote command execution (CVE-2020-10673) jackson-databind: Serialization gadgets in org.aoju.bus.proxy.provider..RmiProvider (CVE-2020-10968) jackson-databind: Serialization gadgets in javax.swing.JEditorPane (CVE-2020-10969) jackson-databind: Serialization gadgets in org.apache.activemq.jms.pool.XaPooledConnectionFactory (CVE-2020-11111) jackson-databind: Serialization gadgets in org.apache.commons.proxy.provider.remoting.RmiProvider (CVE-2020-11112) jackson-databind: Serialization gadgets in org.apache.openjpa.ee.WASRegistryManagedRuntime (CVE-2020-11113) jackson-databind: Serialization gadgets in org.springframework:spring-aop (CVE-2020-11619) jackson-databind: Serialization gadgets in commons-jelly:commons-jelly (CVE-2020-11620) jackson-mapper-asl: XML external entity similar to CVE-2016-3720 (CVE-2019-10172) resteasy: Improper validation of response header in MediaTypeHeaderDelegate.java class (CVE-2020-1695) Wildfly: EJBContext principal is not popped back after invoking another EJB using a different Security Domain (CVE-2020-1719) Wildfly: Improper authorization issue in WildFlySecurityManager when using alternative protection domain (CVE-2020-1748) wildfly-elytron: session fixation when using FORM authentication (CVE-2020-10714) netty: compression/decompression codecs don't enforce limits on buffer allocation sizes (CVE-2020-11612) log4j: improper validation of certificate with host mismatch in SMTP appender (CVE-2020-9488) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Remedy

To install this update, do the following:<br>1. Download the Data Grid 7.3.7 server patch from the customer portal. See the download link in the References section.<br>2. Back up your existing Data Grid installation. You should back up databases, configuration files, and so on.<br>3. Install the Data Grid 7.3.7 server patch. Refer to the 7.3 Release Notes for patching instructions.<br>4. Restart Data Grid to ensure the changes take effect.
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203