CVE-2021-31917

CRITICAL

Infinispan 10.0.0-12.0.0 & Red Hat DataGrid 8.0.0-8.1.1 - DIGEST Auth Bypass

Title source: llm
STIX 2.1

Description

A flaw was found in Red Hat DataGrid 8.x (8.0.0, 8.0.1, 8.1.0 and 8.1.1) and Infinispan (10.0.0 through 12.0.0). An attacker could bypass authentication on all REST endpoints when DIGEST is used as the authentication method. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

References (1)

Core 1
Core References

Scores

CVSS v3 9.8
EPSS 0.0043
EPSS Percentile 62.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-287
Status published
Products (5)
infinispan/infinispan-server-rest 10.0.0 - 11.0.12
redhat/data_grid 8.0.0
redhat/data_grid 8.0.1
redhat/data_grid 8.1.0
redhat/data_grid 8.1.1
Published Sep 21, 2021
Tracked Since Feb 18, 2026