Unsafe reflection in Infinispan - CVE-2019-10174
Published: November 19, 2019
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to Infinispan uses an insecure invokeAccessibly method from ReflectionUtil class that allows to invoke other private methods. A local user can abuse this functionality to execute arbitrary code on the system with privileges of Infinispan process.
Affected software
JBoss A-MQ
Fuse
Red Hat Openshift Application Runtimes
openEuler
Red Hat Single Sign-On
infinispan
infinispan-help
How to mitigate CVE-2019-10174
Fuse - addressed in versions 6.3.15, 7.6.0
Red Hat Single Sign-On - update to 7.3.8
infinispan - update to 8.2.4-13
infinispan-help - update to 8.2.4-13
External References
Related Security Bulletins
- Privilege escalation in Infinispan
- Vert.x 3.8.3 update for Red Hat OpenShift Application Runtimes
- Multiple vulnerabilities in Red Hat JBoss Fuse and A-MQ
- Multiple vulnerabilities in Red Hat Fuse
- openEuler update for infinispan
- openEuler 24.03 LTS update for infinispan
- Multiple vulnerabilities in Red Hat Single Sign-On 7.3