Improper Authentication in Infinispan - CVE-2017-2638
Published: November 19, 2019
Infinispan
Detailed vulnerability description
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to improper enforcement of authentication constrains in the REST API in Infinispan. A remote attacker can send a specially crafted request to the affected application, bypass authentication process and read data or modify data in the default cache or a known cache name.