Infinispan: circular reference on marshalling leads to dos
CVE-2023-5236
6.5MEDIUM
Key Information:
- Vendor
Red Hat
- Vendor
- CVE Published:
- 18 December 2023
What is CVE-2023-5236?
A flaw was found in Infinispan, which does not detect circular object references when unmarshalling. An authenticated attacker with sufficient permissions could insert a maliciously constructed object into the cache and use it to cause out of memory errors and achieve a denial of service.