CVE-2020-25711
published 2020-12-03CVE-2020-25711: A flaw was found in infinispan 10 REST API, where authorization permissions are not checked while performing some server management operations. When authz is…
PriorityP336medium6.5CVSS 3.1
AVNACLPRHUINSUCNIHAH
EPSS
1.07%
61.0th percentile
A flaw was found in infinispan 10 REST API, where authorization permissions are not checked while performing some server management operations. When authz is enabled, any user with authentication can perform operations like shutting down the server without the ADMIN role.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| infinispan | infinispan | < 11.0.6 | 11.0.6 |
| infinispan | infinispan | — | — |
| redhat | data_grid | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
nvdv2.04.9MEDIUMAV:N/AC:M/Au:S/C:N/I:P/A:P
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Improper Access Control in infinispan-server-runtime
osv·2022-02-09
CVE-2020-25711 [MEDIUM] Improper Access Control in infinispan-server-runtime
Improper Access Control in infinispan-server-runtime
A flaw was found in infinispan 10 REST API, where authorization permissions are not checked while performing some server management operations. When authz is enabled, any user with authentication can perform operations like shutting down the server without the ADMIN role.
GHSA
Improper Access Control in infinispan-server-runtime
ghsa·2022-02-09
CVE-2020-25711 [MEDIUM] CWE-269 Improper Access Control in infinispan-server-runtime
Improper Access Control in infinispan-server-runtime
A flaw was found in infinispan 10 REST API, where authorization permissions are not checked while performing some server management operations. When authz is enabled, any user with authentication can perform operations like shutting down the server without the ADMIN role.
Red Hat
infinispan: authorization check missing for server management operations
vendor_redhat·2020-11-13·CVSS 6.5
CVE-2020-25711 [MEDIUM] CWE-862 infinispan: authorization check missing for server management operations
infinispan: authorization check missing for server management operations
A flaw was found in infinispan 10 REST API, where authorization permissions are not checked while performing some server management operations. When authz is enabled, any user with authentication can perform operations like shutting down the server without the ADMIN role.
A flaw was found in the Infinispan 10 REST API, where authorization permissions are not checked while performing some server management operations. When authz is enabled, any user with authentication can perform operations like shutting down the server without the ADMIN role. The highest threat from this vulnerability is to integrity and system availability.
Mitigation: There is currently no known mitigation for this issue.
Package: infinispan-re
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-12-03
Published