CVE-2023-5236

A flaw was found in Infinispan, which does not detect circular object references when unmarshalling. An authenticated attacker with sufficient permissions could insert a maliciously constructed object into the cache and use it to cause out of memory errors and achieve a denial of service.
Configurations

Configuration 1 (hide)

cpe:2.3:a:redhat:data_grid:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:a:redhat:jboss_data_grid:-:*:*:*:text-only:*:*:*

Configuration 3 (hide)

cpe:2.3:a:infinispan:infinispan:-:*:*:*:*:*:*:*

History

25 Jan 2024, 14:15

Type Values Removed Values Added
References
  • () https://security.netapp.com/advisory/ntap-20240125-0004/ -

28 Dec 2023, 20:38

Type Values Removed Values Added
Summary
  • (es) Se encontró una falla en Infinispan, que no detecta referencias de objetos circulares al desarmar. Un atacante autenticado con permisos suficientes podría insertar un objeto construido con fines malintencionados en la memoria caché y utilizarlo para provocar errores de falta de memoria y lograr una denegación de servicio.
References () https://access.redhat.com/errata/RHSA-2023:5396 - () https://access.redhat.com/errata/RHSA-2023:5396 - Vendor Advisory
References () https://access.redhat.com/security/cve/CVE-2023-5236 - () https://access.redhat.com/security/cve/CVE-2023-5236 - Vendor Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=2240999 - () https://bugzilla.redhat.com/show_bug.cgi?id=2240999 - Issue Tracking
CWE NVD-CWE-Other
First Time Redhat data Grid
Infinispan infinispan
Redhat jboss Data Grid
Redhat
Infinispan
CVSS v2 : unknown
v3 : 4.4
v2 : unknown
v3 : 6.5
CPE cpe:2.3:a:redhat:data_grid:*:*:*:*:*:*:*:*
cpe:2.3:a:infinispan:infinispan:-:*:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_data_grid:-:*:*:*:text-only:*:*:*

18 Dec 2023, 15:04

Type Values Removed Values Added
New CVE

Information

Published : 2023-12-18 14:15

Updated : 2024-01-25 14:15


NVD link : CVE-2023-5236

Mitre link : CVE-2023-5236

CVE.ORG link : CVE-2023-5236


JSON object : View

Products Affected

redhat

  • data_grid
  • jboss_data_grid

infinispan

  • infinispan
CWE
NVD-CWE-Other CWE-1047

Modules with Circular Dependencies