CVE-2023-3629

medium

Description

A flaw was found in Infinispan's REST, Cache retrieval endpoints do not properly evaluate the necessary admin permissions for the operation. This issue could allow an authenticated user to access information outside of their intended permissions.

References

https://bugzilla.redhat.com/show_bug.cgi?id=2217926

https://access.redhat.com/security/cve/CVE-2023-3629

https://access.redhat.com/errata/RHSA-2023:5396

Details

Source: Mitre, NVD

Published: 2023-12-18

Updated: 2024-09-16

Risk Information

CVSS v2

Base Score: 6.8

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:N/A:N

Severity: Medium

CVSS v3

Base Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Severity: Medium