CVE-2023-3629
Last modified
CVE-2023-3629 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. A flaw was found in Infinispan's REST, Cache retrieval endpoints do not properly evaluate the necessary admin permissions for the operation. This issue could allow an authenticated user to access information outside of their intended permissions.. EPSS estimates a 0.58% chance of exploitation in the next 30 days.
Description
A flaw was found in Infinispan's REST, Cache retrieval endpoints do not properly evaluate the necessary admin permissions for the operation. This issue could allow an authenticated user to access information outside of their intended permissions.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Data Grid | < 8.4.4 |
| Redhat | Jboss Data Grid | All versions |
| Redhat | Jboss Enterprise Application Platform | 6 |
| Infinispan | Infinispan | All versions |
References
- https://access.redhat.com/errata/RHSA-2023:5396Vendor Advisory
- https://access.redhat.com/security/cve/CVE-2023-3629Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2217926Issue Tracking
- https://access.redhat.com/errata/RHSA-2023:5396Vendor Advisory
- https://access.redhat.com/security/cve/CVE-2023-3629Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2217926Issue Tracking
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-3629?
How severe is CVE-2023-3629?
How do I fix CVE-2023-3629?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-3628A flaw was found in Infinispan's REST. Bulk read endpoints d…6.5
- CVE-2023-36281An issue in langchain v.0.0.171 allows a remote attacker to …9.8
- CVE-2023-36284An unauthenticated Time-Based SQL injection found in Webkul …7.5
- CVE-2023-36287An unauthenticated Cross-Site Scripting (XSS) vulnerability …6.1
- CVE-2023-36288An unauthenticated Cross-Site Scripting (XSS) vulnerability …5.4
- CVE-2023-36289An unauthenticated Cross-Site Scripting (XSS) vulnerability …6.1
- CVE-2023-36291Cross Site Scripting vulnerability in Maxsite CMS v.108.7 al…6.1
- CVE-2023-36293SQL injection vulnerability in wmanager v.1.0.7 and before a…7.5
- CVE-2023-36298DedeCMS v5.7.109 has a File Upload vulnerability, leading to…8.8
- CVE-2023-36299A File Upload vulnerability in typecho v.1.2.1 allows a remo…8.8
- CVE-2023-36301Talend Data Catalog before 8.0-20230221 contain a directory …7.5
- CVE-2023-36306A Cross Site Scripting (XSS) vulnerability in Adiscon Aiscon…6.1
Are you affected by CVE-2023-3629?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
