CVE-2023-5236

A flaw was found in Infinispan, which does not detect circular object references when unmarshalling. An authenticated attacker with sufficient permissions could insert a maliciously constructed object into the cache and use it to cause out of memory errors and achieve a denial of service.
Configurations

Configuration 1 (hide)

cpe:2.3:a:redhat:data_grid:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:a:redhat:jboss_data_grid:-:*:*:*:text-only:*:*:*

Configuration 3 (hide)

cpe:2.3:a:infinispan:infinispan:-:*:*:*:*:*:*:*

History

21 Nov 2024, 08:41

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 6.5
v2 : unknown
v3 : 4.4
References
  • () https://security.netapp.com/advisory/ntap-20240125-0004/ -
References () https://access.redhat.com/errata/RHSA-2023:5396 - Vendor Advisory () https://access.redhat.com/errata/RHSA-2023:5396 - Vendor Advisory
References () https://access.redhat.com/security/cve/CVE-2023-5236 - Vendor Advisory () https://access.redhat.com/security/cve/CVE-2023-5236 - Vendor Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=2240999 - Issue Tracking () https://bugzilla.redhat.com/show_bug.cgi?id=2240999 - Issue Tracking

16 Sep 2024, 14:15

Type Values Removed Values Added
References
  • {'url': 'https://security.netapp.com/advisory/ntap-20240125-0004/', 'source': 'secalert@redhat.com'}

25 Jan 2024, 14:15

Type Values Removed Values Added
References
  • () https://security.netapp.com/advisory/ntap-20240125-0004/ -

28 Dec 2023, 20:38

Type Values Removed Values Added
CWE NVD-CWE-Other
References () https://access.redhat.com/errata/RHSA-2023:5396 - () https://access.redhat.com/errata/RHSA-2023:5396 - Vendor Advisory
References () https://access.redhat.com/security/cve/CVE-2023-5236 - () https://access.redhat.com/security/cve/CVE-2023-5236 - Vendor Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=2240999 - () https://bugzilla.redhat.com/show_bug.cgi?id=2240999 - Issue Tracking
Summary
  • (es) Se encontró una falla en Infinispan, que no detecta referencias de objetos circulares al desarmar. Un atacante autenticado con permisos suficientes podría insertar un objeto construido con fines malintencionados en la memoria caché y utilizarlo para provocar errores de falta de memoria y lograr una denegación de servicio.
CVSS v2 : unknown
v3 : 4.4
v2 : unknown
v3 : 6.5
CPE cpe:2.3:a:infinispan:infinispan:-:*:*:*:*:*:*:*
cpe:2.3:a:redhat:data_grid:*:*:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_data_grid:-:*:*:*:text-only:*:*:*
First Time Infinispan infinispan
Infinispan
Redhat
Redhat jboss Data Grid
Redhat data Grid

18 Dec 2023, 15:04

Type Values Removed Values Added
New CVE

Information

Published : 2023-12-18 14:15

Updated : 2024-11-21 08:41


NVD link : CVE-2023-5236

Mitre link : CVE-2023-5236

CVE.ORG link : CVE-2023-5236


JSON object : View

Products Affected

redhat

  • data_grid
  • jboss_data_grid

infinispan

  • infinispan
CWE
CWE-1047

Modules with Circular Dependencies

NVD-CWE-Other