CVE-2020-25711
Last modified
CVE-2020-25711 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. A flaw was found in infinispan 10 REST API, where authorization permissions are not checked while performing some server management operations. When authz is enabled, any user with authentication can perform operations like shutting down the server without the ADMIN role.. EPSS estimates a 1.07% chance of exploitation in the next 30 days.
Description
A flaw was found in infinispan 10 REST API, where authorization permissions are not checked while performing some server management operations. When authz is enabled, any user with authentication can perform operations like shutting down the server without the ADMIN role.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Infinispan | Infinispan | < 11.0.6 |
| Redhat | Data Grid | 8.0 |
| Netapp | Active Iq Unified Manager | All versions |
References
- https://bugzilla.redhat.com/show_bug.cgi?id=1897618Issue Tracking, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20220210-0023/Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1897618Issue Tracking, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20220210-0023/Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-25711?
How severe is CVE-2020-25711?
How do I fix CVE-2020-25711?
Are you affected by CVE-2020-25711?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
