CVE-2023-5236

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
18/12/2023
Last modified:
25/09/2025

Description

A flaw was found in Infinispan, which does not detect circular object references when unmarshalling. An authenticated attacker with sufficient permissions could insert a maliciously constructed object into the cache and use it to cause out of memory errors and achieve a denial of service.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:redhat:data_grid:*:*:*:*:*:*:*:* 8.4.4 (excluding)
cpe:2.3:a:redhat:jboss_data_grid:-:*:*:*:text-only:*:*:*
cpe:2.3:a:infinispan:infinispan:-:*:*:*:*:*:*:*