CVE-2018-1131

HIGH

Infinispan <9.3.0 - Code Execution

Title source: llm

Description

Infinispan permits improper deserialization of trusted data via XML and JSON transcoders under certain server configurations. A user with authenticated access to the server could send a malicious object to a cache configured to accept certain types of objects, achieving code execution and possible further attacks. Versions 9.0.3.Final, 9.1.7.Final, 8.2.10.Final, 9.2.2.Final, 9.3.0.Alpha1 are believed to be affected.

Scores

CVSS v3 8.8
EPSS 0.0053
EPSS Percentile 66.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-502 CWE-349
Status published

Affected Products (7)

infinispan/infinispan
infinispan/infinispan
infinispan/infinispan
infinispan/infinispan
infinispan/infinispan
redhat/jboss_data_grid
org.infinispan/infinispan-core Maven

Timeline

Published May 15, 2018
Tracked Since Feb 18, 2026