Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Infinispan permits improper deserialization of trusted data via XML and JSON transcoders under certain server configurations. A user with authenticated access to the server could send a malicious object to a cache configured to accept certain types of objects, achieving code execution and possible further attacks. Versions 9.0.3.Final, 9.1.7.Final, 8.2.10.Final, 9.2.2.Final, 9.3.0.Alpha1 are believed to be affected.
CVSS Information
N/A
Vulnerability Type
在可信数据中接受外来的不可信数据
Vulnerability Title
Infinispan 安全漏洞
Vulnerability Description
Infinispan是Infinispan团队的一套基于Java的开源的分布式数据存储和数据网格平台。 Infinispan中存在安全漏洞,该漏洞源于程序通过XML和JSON编码器没有正确的反序列化可信的数据。攻击者可通过向缓存中发送恶意的对象利用该漏洞执行代码。以下版本受到影响:Infinispan 9.0.3.Final版本,9.1.7.Final版本,8.2.10.Final版本,9.2.2.Final版本,9.3.0.Alpha1版本。
CVSS Information
N/A
Vulnerability Type
N/A