Infinispan circular object references causes out of memory errors
Moderate severity
GitHub Reviewed
Published
Dec 28, 2023
to the GitHub Advisory Database
•
Updated Sep 16, 2024
Package
Affected versions
< 4.6.2.Final
Patched versions
4.6.2.Final
Description
Published by the National Vulnerability Database
Dec 18, 2023
Published to the GitHub Advisory Database
Dec 28, 2023
Reviewed
Sep 16, 2024
Last updated
Sep 16, 2024
A flaw was found in Infinispan, which does not detect circular object references when unmarshalling. An authenticated attacker with sufficient permissions could insert a maliciously constructed object into the cache and use it to cause out of memory errors and achieve a denial of service.
References