A flaw was found in Infinispan version 10, where it is possible to perform various actions that could have side effects using GET requests. This flaw allows an attacker to perform a cross-site request forgery (CSRF) attack.
2021-06-02T12:15:07.397
2024-11-21T04:56:02.263
Modified
CVSSv3.1: 7.1 (HIGH)
AV:N/AC:M/Au:N/C:N/I:P/A:P
8.6
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | infinispan | infinispan-server-rest | 10.0.0 | Yes |
Application | redhat | data_grid | 8.0 | Yes |
Application | netapp | oncommand_insight | - | Yes |