VDB
CVE-2020-10771
CVE-2020-10771
PUBLISHED
CVSS 7.099999904632568 HIGH
A flaw was found in Infinispan version 10, where it is possible to perform various actions that could have side effects using GET requests. This flaw allows an attacker to perform a cross-site request forgery (CSRF) attack.
EPSS 0.09% · 24.7th percentile
Risk Scores
CVSS 3.1
7.099999904632568
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H
EPSS Score
0.09%
24.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| netapp | oncommand_insight | |
| n/a | Infinispan | Red Hat Data Grid 8.2.0 |
| redhat | data_grid | 8.0 |
| infinispan | infinispan-server-rest | 10.0.0 |
Exploit Intelligence
Timeline
- Jun 2, 2021 EPSS Score
- Jun 2, 2021 CVE Published
- Aug 4, 2021 EPSS Score
- Oct 4, 2021 EPSS Score
- Dec 4, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- Apr 5, 2022 EPSS Score
- Jun 5, 2022 EPSS Score
- Aug 6, 2022 EPSS Score
- Oct 6, 2022 EPSS Score
- Dec 6, 2022 EPSS Score
References
- https://bugzilla.redhat.com/show_bug.cgi?id=1846293 url
- https://security.netapp.com/advisory/ntap-20210827-0003/ url
- https://access.redhat.com/errata/RHSA-2021:2139 advisory
- https://access.redhat.com/errata/RHSA-2021:2106 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-10771 advisory
- https://security.netapp.com/advisory/ntap-20210827-0003 url