CVE-2020-25711
Last modified
CVE-2020-25711 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. A flaw was found in infinispan 10 REST API, where authorization permissions are not checked while performing some server management operations. When authz is enabled, any user with authentication can perform operations like shutting down the server without the ADMIN role.. EPSS estimates a 1.07% chance of exploitation in the next 30 days.
Description
A flaw was found in infinispan 10 REST API, where authorization permissions are not checked while performing some server management operations. When authz is enabled, any user with authentication can perform operations like shutting down the server without the ADMIN role.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Infinispan | Infinispan | < 11.0.6 |
| Redhat | Data Grid | 8.0 |
| Netapp | Active Iq Unified Manager | All versions |
References
- https://bugzilla.redhat.com/show_bug.cgi?id=1897618Issue Tracking, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20220210-0023/Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1897618Issue Tracking, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20220210-0023/Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-25711?
How severe is CVE-2020-25711?
How do I fix CVE-2020-25711?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-25706A cross-site scripting (XSS) vulnerability exists in templat…6.1
- CVE-2020-25707Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: T…
- CVE-2020-25708A divide by zero issue was found to occur in libvncserver-0.…7.5
- CVE-2020-25709A flaw was found in OpenLDAP. This flaw allows an attacker w…7.5
- CVE-2020-2571Vulnerability in the Oracle VM Server for SPARC product of O…3.3
- CVE-2020-25710A flaw was found in OpenLDAP in versions before 2.4.56. This…7.5
- CVE-2020-25712A flaw was found in xorg-x11-server before 1.20.10. A heap-b…7.8
- CVE-2020-25713A malformed input file can lead to a segfault due to an out …6.5
- CVE-2020-25714Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2020-25715A flaw was found in pki-core 10.9.0. A specially crafted POS…6.1
- CVE-2020-25716A flaw was found in Cloudforms. A role-based privileges esca…8.1
- CVE-2020-25717A flaw was found in the way Samba maps domain users to local…8.1
Are you affected by CVE-2020-25711?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
