Infinispan permits improper deserialization of trusted data via XML and JSON transcoders under certain server configurations. A user with authenticated access to the server could send a malicious object to a cache configured to accept certain types of objects, achieving code execution and possible further attacks. Versions 9.0.3.Final, 9.1.7.Final, 8.2.10.Final, 9.2.2.Final, 9.3.0.Alpha1 are believed to be affected.
📦
infinispan
Vendor: infinispan
Actively Exploited
0
CISA KEV List
PoC / Exploits
0
Code Available
Total RCEs
3
Remote Access
Total CVEs
14
Total Indexed
Avg. EPSS
1.41%
Exploit Prob.
Security Vulnerability Index
Page 2 / 2
8.8
CVSS
CVE-2018-1131
RCE
Severity: HIGH
8.8
CVSS
CVE-2017-15089
RCE
It was found that the Hotrod client in Infinispan before 9.2.0.CR1 would unsafely read deserialized data on information from the cache. An authenticated attacker could inject a malicious object into the data cache and attain deserialization on the client, and possibly conduct further attacks.
Severity: HIGH