CVE-2023-5236
18.12.2023, 14:15
A flaw was found in Infinispan, which does not detect circular object references when unmarshalling. An authenticated attacker with sufficient permissions could insert a maliciously constructed object into the cache and use it to cause out of memory errors and achieve a denial of service.Enginsight
Vendor | Product | Version |
---|---|---|
redhat | data_grid | 𝑥 < 8.4.4 |
redhat | jboss_data_grid | - |
infinispan | infinispan | - |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References