CVE-2017-2638
Infinispan Rest API Does Not Enforce Auth Constraints
6.5
MEDIUM
CVSS 3.1
EPSS 0.50%
Description
It was found that the REST API in Infinispan before version 9.0.0 did not properly enforce auth constraints. An attacker could use this vulnerability to read or modify data in the default cache or a known cache name.
How to fix CVE-2017-2638
To remediate CVE-2017-2638, upgrade the affected package to a fixed version below.
- Maven/org.infinispan:infinispan-server-core—upgrade to 9.0.0 or later
Is CVE-2017-2638 being exploited?
Low — EPSS is 0.5%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 9.0.0
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.5 | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |