Deserialization of Untrusted Data in Infinispan
High severity
GitHub Reviewed
Published
May 14, 2022
to the GitHub Advisory Database
•
Updated May 10, 2023
Package
Affected versions
<= 9.2.0.Beta2
Patched versions
9.2.0.CR1
Description
Published by the National Vulnerability Database
Feb 15, 2018
Published to the GitHub Advisory Database
May 14, 2022
Reviewed
Jul 1, 2022
Last updated
May 10, 2023
It was found that the Hotrod client in Infinispan before 9.2.0.CR1 would unsafely read deserialized data on information from the cache. An authenticated attacker could inject a malicious object into the data cache and attain deserialization on the client, and possibly conduct further attacks.
References