Infinispan is a distributed caching and data-grid platform widely embedded in enterprise middleware and application servers, particularly within the JBoss and Red Hat ecosystem. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity; the exposure centers on the core Infinispan cache server and its REST and Hot Rod protocol endpoints, and recurs through weakness classes including deserialization of untrusted data, improper authentication, and missing authorization checks that are characteristic of remote-access middleware. Defenders should treat Infinispan updates as high-priority within their application-server inventory and focus on controls around cache-server network exposure; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Infinispan over time
Signals from CVEs in this vendor scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-31917CRITICAL A flaw was found in Red Hat DataGrid 8.x (8.0.0, 8.0.1, 8.1.0 and 8.1.1) and Infinispan (10.0.0 through 12.0.0). An attacker could bypass authentication on all REST endpoints when | Sep 21, 2021 | 9.8 | 30 | NO | NO |
CVE-2019-10158CRITICAL A flaw was found in Infinispan through version 9.4.14.Final. An improper implementation of the session fixation protection in the Spring Session integration can result in incorrect | Jan 2, 2020 | 9.8 | 30 | NO | NO |
CVE-2019-10174HIGH A vulnerability was found in Infinispan such that the invokeAccessibly method from the public class ReflectionUtil allows any application class to invoke private methods in any cla | Nov 25, 2019 | 8.8 | 29 | NO | NO |
CVE-2016-0750HIGH The hotrod java client in infinispan before 9.1.0.Final automatically deserializes bytearray message contents in certain events. A malicious user could exploit this flaw by injecti | Sep 11, 2018 | 8.8 | 28 | NO | NO |
CVE-2017-15089HIGH It was found that the Hotrod client in Infinispan before 9.2.0.CR1 would unsafely read deserialized data on information from the cache. An authenticated attacker could inject a mal | Feb 15, 2018 | 8.8 | 27 | NO | NO |
CVE-2018-1131HIGH Infinispan permits improper deserialization of trusted data via XML and JSON transcoders under certain server configurations. A user with authenticated access to the server could s | May 15, 2018 | 8.8 | 26 | NO | NO |
CVE-2020-10771HIGH A flaw was found in Infinispan version 10, where it is possible to perform various actions that could have side effects using GET requests. This flaw allows an attacker to perform | Jun 2, 2021 | 7.1 | 24 | NO | NO |
CVE-2017-2638MEDIUM It was found that the REST API in Infinispan before version 9.0.0 did not properly enforce auth constraints. An attacker could use this vulnerability to read or modify data in the | Jul 16, 2018 | 6.5 | 23 | NO | NO |
CVE-2023-4586HIGH A vulnerability was found in the Hot Rod client. This security issue occurs as the Hot Rod client does not enable hostname validation when using TLS, possibly resulting in a man-in | Oct 4, 2023 | 7.4 | 22 | NO | NO |
CVE-2020-25711MEDIUM A flaw was found in infinispan 10 REST API, where authorization permissions are not checked while performing some server management operations. When authz is enabled, any user with | Dec 3, 2020 | 6.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (16 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Infinispan.
Media articles that mention a CVE ID that affects a product developed by Infinispan — matched by CVE ID, not by vendor name.