A flaw was found in Infinispan through version 9.4.14.Final. An improper implementation of the session fixation protection in the Spring Session integration can result in incorrect session handling.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HInfinispan
APPInfinispan≤ 9.4.14Red Hat Jboss Data Grid
APPRedhat7.0.0
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
References
Related vulnerabilities
CVE-2019-14887CRITICAL9.1PL ✓same product
Wildfly: ignorowanie 'enabled-protocols' umożliwia TLS downgrade
CVE-2019-14892CRITICAL9.8PL ✓same product
RCE poprzez deserializację JNDI w jackson-databind (commons-configuration)
CVE-2019-10212CRITICAL9.8PL ✓same product
Undertow: ujawnienie poświadczeń użytkownika w logach DEBUG
CVE-2019-3888CRITICAL9.8PL ✓same product
Undertow: ujawnienie danych uwierzytelniających w plikach logów
CVE-2023-5384HIGH7.2same product
A flaw was found in Infinispan. When serializing the configuration for a cache to XML/JSON/YAML, which contain...