Red Hat Bugzilla – Bug 1576492
CVE-2018-1131 infinispan: deserialization of data in XML and JSON transcoders
Last modified: 2018-10-19 17:49:10 EDT
Infinispan permits improper deserialization of trusted data via XML and JSON transcoders under certain server configurations. A user with authenticated access to the server could send a malicious object to a cache configured to accept certain types of objects, achieving code execution and possible further attacks.
This issue has been addressed in the following products: Red Hat Data Grid Via RHSA-2018:1833 https://access.redhat.com/errata/RHSA-2018:1833