Infinispan Infinispan-server-rest 10.0.0

CPE Details

Infinispan Infinispan-server-rest 10.0.0
10.0.0
2021-11-30
12h47 +00:00
2022-09-19
13h58 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:infinispan:infinispan-server-rest:10.0.0:*:*:*:*:*:*:*

Informations

Vendor

infinispan

Product

infinispan-server-rest

Version

10.0.0

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2021-31917 2021-09-21 08h33 +00:00 A flaw was found in Red Hat DataGrid 8.x (8.0.0, 8.0.1, 8.1.0 and 8.1.1) and Infinispan (10.0.0 through 12.0.0). An attacker could bypass authentication on all REST endpoints when DIGEST is used as the authentication method. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
9.8
Critical
CVE-2020-10771 2021-06-02 09h02 +00:00 A flaw was found in Infinispan version 10, where it is possible to perform various actions that could have side effects using GET requests. This flaw allows an attacker to perform a cross-site request forgery (CSRF) attack.
7.1
High