← Back

CVE-2023-3628

nvd nist
Published: Dec 18, 2023Modified: Jun 17, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

A flaw was found in Infinispan's REST. Bulk read endpoints do not properly evaluate user permissions for the operation. This issue could allow an authenticated user to access information outside of their intended permissions.

Affected (4)

3 products
Jboss Data Grid
Data Grid
1 product
Infinispan
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
All versions
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 6
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 8.4.4
Configuration D
1 vulnerable
Vulnerable SoftwareAffected Versions
All versions

References (7)

Source: secalert@redhat.com
Vendor Advisory
Source: secalert@redhat.com
Vendor Advisory
Source: secalert@redhat.com
Issue Tracking
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.