Deserialization of Untrusted Data in Infinispan
High severity
GitHub Reviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Jan 27, 2023
Package
Affected versions
= 8.2.10.Final
= 9.0.3.Final
= 9.1.7.Final
= 9.2.2.Final
= 9.3.0.Alpha1
Patched versions
9.3.1.Final
Description
Published by the National Vulnerability Database
May 15, 2018
Published to the GitHub Advisory Database
May 13, 2022
Reviewed
Jun 29, 2022
Last updated
Jan 27, 2023
Infinispan permits improper deserialization of trusted data via XML and JSON transcoders under certain server configurations. A user with authenticated access to the server could send a malicious object to a cache configured to accept certain types of objects, achieving code execution and possible further attacks. Versions 9.0.3.Final, 9.1.7.Final, 8.2.10.Final, 9.2.2.Final, 9.3.0.Alpha1 are believed to be affected.
References