CVE-2020-25711: Infinispan

Medium severity, CVSS 6.5. EPSS: 1.1% chance of exploitation in the next 30 days.

A flaw was found in infinispan 10 REST API, where authorization permissions are not checked while performing some server management operations. When authz is enabled, any user with authentication can perform operations like shutting down the server without the ADMIN role.

Affected products

  • Infinispan Infinispan: before 11.0.6 (fixed in 11.0.6)
  • Netapp Active Iq Unified Manager: affected versions not specified
  • Red Hat Data Grid: version 8.0 only

Published 2020-12-03. Last modified 2026-06-17.