A flaw was found in Infinispan version 10, where it is possible to perform various actions that could have side effects using GET requests. This flaw allows an attacker to perform a cross-site request forgery (CSRF) attack.
Software | From | Fixed in |
---|---|---|
redhat / data_grid | 8.0 | 8.0.x |
infinispan / infinispan-server-rest | 10.0.0 | 10.0.0.x |