CRITICAL🇵🇱 Wersja polska

CVE-2021-31917

CVSS 9.8v3.1pub. 2021-09-21upd. 2024-11-21

A flaw was found in Red Hat DataGrid 8.x (8.0.0, 8.0.1, 8.1.0 and 8.1.1) and Infinispan (10.0.0 through 12.0.0). An attacker could bypass authentication on all REST endpoints when DIGEST is used as the authentication method. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Infinispan Server Rest

    APP
    Infinispan
    10.0.0 – 11.0.12 (excl.)12.0.0 – 12.1.4 (excl.)
  • Red Hat Data Grid

    APP
    Redhat
    8.0.08.0.18.1.08.1.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2025-12543CRITICAL9.6PL ✓same product

Brak walidacji nagłówka Host w serwerze Undertow HTTP

CVE-2015-7501CRITICAL9.8PL ✓same product

RCE przez deserializację obiektów Java w produktach Red Hat (Apache Commons Collections)

CVE-2026-15573HIGH8.1PL ✓same product

Keycloak: ominięcie polityki bezpieczeństwa przez nieprawidłową normalizację URI

CVE-2026-16102HIGH8.1PL ✓same product

Keycloak DCR: fałszowanie ról administracyjnych przez User Property mapper

CVE-2026-44495HIGH7.0same product

Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axi...