A flaw was found in Red Hat DataGrid 8.x (8.0.0, 8.0.1, 8.1.0 and 8.1.1) and Infinispan (10.0.0 through 12.0.0). An attacker could bypass authentication on all REST endpoints when DIGEST is used as the authentication method. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: redhat

Published: 2021-09-21T10:33:41

Updated: 2021-09-21T10:33:41

Reserved: 2021-04-29T00:00:00


Link: CVE-2021-31917

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2021-09-21T11:15:07.953

Modified: 2022-01-11T16:21:41.567


Link: CVE-2021-31917

JSON object: View

cve-icon Redhat Information

No data.

CWE