HIGH · 7.1

CVE-2020-10771

A flaw was found in Infinispan version 10, where it is possible to perform various actions that could have side effects using GET requests. This flaw allows an attacker to perform a cross-site request...

Vulnerability Description

A flaw was found in Infinispan version 10, where it is possible to perform various actions that could have side effects using GET requests. This flaw allows an attacker to perform a cross-site request forgery (CSRF) attack.

CVSS Score

7.1

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
NONE
Integrity
LOW
Availability
HIGH

Affected Products

VendorProductVersions
InfinispanInfinispan-Server-Rest10.0.0
RedhatData Grid8.0
NetappOncommand Insight-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-10771?

CVE-2020-10771 is a vulnerability with a CVSS score of 7.1 (HIGH). A flaw was found in Infinispan version 10, where it is possible to perform various actions that could have side effects using GET requests. This flaw allows an attacker to perform a cross-site request...

How severe is CVE-2020-10771?

CVE-2020-10771 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-10771?

Check the references section above for vendor advisories and patch information. Affected products include: Infinispan Infinispan-Server-Rest, Redhat Data Grid, Netapp Oncommand Insight.