A flaw was found in Red Hat DataGrid 8.x (8.0.0, 8.0.1, 8.1.0 and 8.1.1) and Infinispan (10.0.0 through 12.0.0). An attacker could bypass authentication on all REST endpoints when DIGEST is used as the authentication method. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HInfinispan Server Rest
APPInfinispan10.0.0 – 11.0.12 (excl.)12.0.0 – 12.1.4 (excl.)Red Hat Data Grid
APPRedhat8.0.08.0.18.1.08.1.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
Related vulnerabilities
CVE-2025-12543CRITICAL9.6PL ✓same product
Brak walidacji nagłówka Host w serwerze Undertow HTTP
CVE-2015-7501CRITICAL9.8PL ✓same product
RCE przez deserializację obiektów Java w produktach Red Hat (Apache Commons Collections)
CVE-2026-15573HIGH8.1PL ✓same product
Keycloak: ominięcie polityki bezpieczeństwa przez nieprawidłową normalizację URI
CVE-2026-16102HIGH8.1PL ✓same product
Keycloak DCR: fałszowanie ról administracyjnych przez User Property mapper
CVE-2026-44495HIGH7.0same product
Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axi...