CVE-2023-3629
published 2023-12-18CVE-2023-3629: A flaw was found in Infinispan's REST, Cache retrieval endpoints do not properly evaluate the necessary admin permissions for the operation. This issue could…
PriorityP434medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
0.58%
43.8th percentile
A flaw was found in Infinispan's REST, Cache retrieval endpoints do not properly evaluate the necessary admin permissions for the operation. This issue could allow an authenticated user to access information outside of their intended permissions.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | data_grid | < 8.4.4 | 8.4.4 |
| redhat | jboss_enterprise_application_platform | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Infinispan REST Server's cache retrieval endpoints do not properly evaluate the necessary admin permissions
ghsa·2023-12-30
CVE-2023-3629 [HIGH] CWE-304 Infinispan REST Server's cache retrieval endpoints do not properly evaluate the necessary admin permissions
Infinispan REST Server's cache retrieval endpoints do not properly evaluate the necessary admin permissions
A flaw was found in Infinispan's REST, Cache retrieval endpoints do not properly evaluate the necessary admin permissions for the operation. This issue could allow an authenticated user to access information outside of their intended permissions.
OSV
Infinispan REST Server's cache retrieval endpoints do not properly evaluate the necessary admin permissions
osv·2023-12-30
CVE-2023-3629 [HIGH] Infinispan REST Server's cache retrieval endpoints do not properly evaluate the necessary admin permissions
Infinispan REST Server's cache retrieval endpoints do not properly evaluate the necessary admin permissions
A flaw was found in Infinispan's REST, Cache retrieval endpoints do not properly evaluate the necessary admin permissions for the operation. This issue could allow an authenticated user to access information outside of their intended permissions.
Red Hat
infinispan: Non-admins should not be able to get cache config via REST API
vendor_redhat·2023-09-21·CVSS 4.3
CVE-2023-3629 [MEDIUM] CWE-304 infinispan: Non-admins should not be able to get cache config via REST API
infinispan: Non-admins should not be able to get cache config via REST API
A flaw was found in Infinispan's REST, Cache retrieval endpoints do not properly evaluate the necessary admin permissions for the operation. This issue could allow an authenticated user to access information outside of their intended permissions.
A flaw was found in Infinispan's REST, Cache retrieval endpoints do not properly evaluate the necessary admin permissions for the operation. This issue could allow an authenticated user to access information outside of their intended permissions.
Package: infinispan (Red Hat JBoss Enterprise Application Platform 6) - Out of support scope
No detection rules found.
No public exploits indexed.
https://access.redhat.com/errata/RHSA-2023:5396https://access.redhat.com/security/cve/CVE-2023-3629https://bugzilla.redhat.com/show_bug.cgi?id=2217926https://access.redhat.com/errata/RHSA-2023:5396https://access.redhat.com/security/cve/CVE-2023-3629https://bugzilla.redhat.com/show_bug.cgi?id=2217926https://security.netapp.com/advisory/ntap-20240125-0004/
2023-12-18
Published