CVE-2018-1131
Last modified
CVE-2018-1131 is a vulnerability of currently unknown severity. Infinispan permits improper deserialization of trusted data via XML and JSON transcoders under certain server configurations. A user with authenticated access to the server could send a malicious object to a cache configured to accept certain types of objects, achieving code execution and possible further attacks. EPSS estimates a 1.27% chance of exploitation in the next 30 days.
Description
Infinispan permits improper deserialization of trusted data via XML and JSON transcoders under certain server configurations. A user with authenticated access to the server could send a malicious object to a cache configured to accept certain types of objects, achieving code execution and possible further attacks. Versions 9.0.3.Final, 9.1.7.Final, 8.2.10.Final, 9.2.2.Final, 9.3.0.Alpha1 are believed to be affected.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Infinispan | Infinispan | 8.2.10 | — |
| Infinispan | Infinispan | 9.0.3 | — |
| Infinispan | Infinispan | 9.1.7 | — |
| Infinispan | Infinispan | 9.2.2 | — |
| Infinispan | Infinispan | 9.3.0 | Alpha1 |
| Redhat | Jboss Data Grid | 7.2 | — |
References
- http://www.securityfocus.com/bid/104218Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2018:1833Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1576492Issue Tracking, Third Party Advisory
- http://www.securityfocus.com/bid/104218Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2018:1833Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1576492Issue Tracking, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-1131?
How severe is CVE-2018-1131?
How do I fix CVE-2018-1131?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-11303Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2018-11304Possible buffer overflow in msm_adsp_stream_callback_put due…
- CVE-2018-11305When a series of FDAL messages are sent to the modem, a Use …
- CVE-2018-11306Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2018-11307An issue was discovered in FasterXML jackson-databind 2.0.0 …9.8
- CVE-2018-11309Blind SQL injection in coupon_code in the MemberMouse plugin…
- CVE-2018-11311A hardcoded FTP username of myscada and password of Vikuk63 …
- CVE-2018-11314The External Control API in Roku and Roku TV products allow …
- CVE-2018-11315The Local HTTP API in Radio Thermostat CT50 and CT80 1.04.84…
- CVE-2018-11316The UPnP HTTP server on Sonos wireless speaker products allo…
- CVE-2018-11317Subrion CMS before 4.1.4 has XSS.
- CVE-2018-11319Syntastic (aka vim-syntastic) through 3.9.0 does not properl…
Are you affected by CVE-2018-1131?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
