CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2019-10158

CVSS 9.8v3.1pub. 2020-01-02upd. 2024-11-21

A flaw was found in Infinispan through version 9.4.14.Final. An improper implementation of the session fixation protection in the Spring Session integration can result in incorrect session handling.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Infinispan

    APP
    Infinispan
    ≤ 9.4.14
  • Red Hat Jboss Data Grid

    APP
    Redhat
    7.0.0
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2019-14887CRITICAL9.1PL ✓same product

Wildfly: ignorowanie 'enabled-protocols' umożliwia TLS downgrade

CVE-2019-14892CRITICAL9.8PL ✓same product

RCE poprzez deserializację JNDI w jackson-databind (commons-configuration)

CVE-2019-10212CRITICAL9.8PL ✓same product

Undertow: ujawnienie poświadczeń użytkownika w logach DEBUG

CVE-2019-3888CRITICAL9.8PL ✓same product

Undertow: ujawnienie danych uwierzytelniających w plikach logów

CVE-2023-5384HIGH7.2same product

A flaw was found in Infinispan. When serializing the configuration for a cache to XML/JSON/YAML, which contain...