Use of Externally-Controlled Input to Select Classes or Code in Infinispan
High severity
GitHub Reviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated Jan 27, 2023
Package
Affected versions
<= 8.2.11.Final
>= 9.0.0.Final, <= 9.4.16.Final
Patched versions
8.2.12.Final
9.4.17.Final
Description
Published by the National Vulnerability Database
Nov 25, 2019
Published to the GitHub Advisory Database
May 24, 2022
Reviewed
Jun 29, 2022
Last updated
Jan 27, 2023
A vulnerability was found in Infinispan such that the invokeAccessibly method from the public class ReflectionUtil allows any application class to invoke private methods in any class with Infinispan's privileges. The attacker can use reflection to introduce new, malicious behavior into the application.
References