CVE-2023-5236
published 2023-12-18CVE-2023-5236: A flaw was found in Infinispan, which does not detect circular object references when unmarshalling. An authenticated attacker with sufficient permissions…
PriorityP431medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
0.89%
55.3th percentile
A flaw was found in Infinispan, which does not detect circular object references when unmarshalling. An authenticated attacker with sufficient permissions could insert a maliciously constructed object into the cache and use it to cause out of memory errors and achieve a denial of service.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | data_grid | < 8.4.4 | 8.4.4 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
vendor_redhat4.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
infinispan: circular reference on marshalling leads to DoS
vendor_redhat·2023-09-27·CVSS 4.4
CVE-2023-5236 [MEDIUM] infinispan: circular reference on marshalling leads to DoS
infinispan: circular reference on marshalling leads to DoS
A flaw was found in Infinispan, which does not detect circular object references when unmarshalling. An authenticated attacker with sufficient permissions could insert a maliciously constructed object into the cache and use it to cause out of memory errors and achieve a denial of service.
A flaw was found in Infinispan, which does not detect circular object references when unmarshalling. An authenticated attacker with sufficient permissions could insert a maliciously constructed object into the cache and use it to cause out of memory errors and achieve a denial of service.
Package: protostream (Red Hat build of Apache Camel 4 for Quarkus 3) - Fix deferred
Package: protostream-processor (Red Hat build of Apache Camel 4 for Quark
OSV
Infinispan circular object references causes out of memory errors
osv·2023-12-28
CVE-2023-5236 [HIGH] Infinispan circular object references causes out of memory errors
Infinispan circular object references causes out of memory errors
A flaw was found in Infinispan, which does not detect circular object references when unmarshalling. An authenticated attacker with sufficient permissions could insert a maliciously constructed object into the cache and use it to cause out of memory errors and achieve a denial of service.
GHSA
Infinispan circular object references causes out of memory errors
ghsa·2023-12-28
CVE-2023-5236 [HIGH] CWE-1047 Infinispan circular object references causes out of memory errors
Infinispan circular object references causes out of memory errors
A flaw was found in Infinispan, which does not detect circular object references when unmarshalling. An authenticated attacker with sufficient permissions could insert a maliciously constructed object into the cache and use it to cause out of memory errors and achieve a denial of service.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://access.redhat.com/errata/RHSA-2023:5396https://access.redhat.com/security/cve/CVE-2023-5236https://bugzilla.redhat.com/show_bug.cgi?id=2240999https://access.redhat.com/errata/RHSA-2023:5396https://access.redhat.com/security/cve/CVE-2023-5236https://bugzilla.redhat.com/show_bug.cgi?id=2240999https://security.netapp.com/advisory/ntap-20240125-0004/
2023-12-18
Published