CVEs (2)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Infinispan Redhat2Data Grid Infinispan Server RestNov 21, 2024 Sep 21, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A flaw was found in Red Hat DataGrid 8.x (8.0.0, 8.0.1, 8.1.0 and 8.1.1) and Infinispan (10.0.0 through 12.0.0). An attacker could bypass authentication on all REST endpoints when DIGEST is used as the authentication met...Show more |
3Infinispan NetappRedhat3Data Grid Infinispan Server RestOncommand InsightNov 21, 2024 Jun 2, 2021 N/A· v4 7.1 HIGH· v3 5.8 MEDIUM· v2 A flaw was found in Infinispan version 10, where it is possible to perform various actions that could have side effects using GET requests. This flaw allows an attacker to perform a cross-site request forgery (CSRF) atta...Show more |