CVE-2023-3628: Infinispan
Medium severity, CVSS 6.5. EPSS: 0.8% chance of exploitation in the next 30 days.
A flaw was found in Infinispan's REST. Bulk read endpoints do not properly evaluate user permissions for the operation. This issue could allow an authenticated user to access information outside of their intended permissions.
Affected products
- Infinispan Infinispan: affected versions not specified
- Red Hat Data Grid: before 8.4.4 (fixed in 8.4.4)
- Red Hat JBoss Data Grid: affected versions not specified
- Red Hat JBoss Enterprise Application Platform: version 6 only
Published 2023-12-18. Last modified 2026-06-17.