CVE-2020-10746 - CERT CVE
ID CVE-2020-10746
Sažetak A flaw was found in Infinispan (org.infinispan:infinispan-server-runtime) version 10, where it permits local access to controls via both REST and HotRod APIs. This flaw allows a user authenticated to the local machine to perform all operations on the caches, including the creation, update, deletion, and shutdown of the entire server.
Reference
CVSS
Base: 5.6
Impact: 7.8
Exploitability:3.9
Pristup
VektorSloženostAutentikacija
LOCAL LOW NONE
Impact
PovjerljivostCjelovitostDostupnost
NONE PARTIAL COMPLETE
CVSS vektor AV:L/AC:L/Au:N/C:N/I:P/A:C
Zadnje važnije ažuriranje 26-10-2021 - 20:13
Objavljeno 19-10-2020 - 21:15