org.infinispan:infinispan-core@9.3.0.Alpha1 vulnerabilities

Direct Vulnerabilities

Known vulnerabilities in the org.infinispan:infinispan-core package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • H
Deserialization of Untrusted Data

org.infinispan:infinispan-core is a data grid platform and highly scalable NoSQL cloud data store.

Affected versions of this package are vulnerable to Deserialization of Untrusted Data via XML and JSON transcoders under certain server configurations. A user with authenticated access to the server could send a malicious object to a cache configured to accept certain types of objects, achieving code execution and possible further attacks.

How to fix Deserialization of Untrusted Data?

Upgrade org.infinispan:infinispan-core to version 9.3.0.Final or higher.

[7.0.0.Final,9.3.0.Final)