Hot Rod是Infinispan组织的一种 Infinispan 客户端用于与远程网格通信的有线协议。 Hot Rod存在安全漏洞,该漏洞源于在使用TLS时未启用主机名验证,可能会导致中间人攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Data Grid 8.4.6 | - |
cpe:/a:redhat:jboss_data_grid:8
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-39191 | 8.2 HIGH | Kernel: ebpf: insufficient stack type checks in dynptr |
| CVE-2023-3971 | 7.3 HIGH | Controller: html injection in custom login info |
| CVE-2023-4237 | 7.3 HIGH | Platform: ec2_key module prints out the private key directly to the standard output |
| CVE-2023-4380 | 6.3 MEDIUM | Platform: token exposed at importing project |
| CVE-2023-3428 | 6.2 MEDIUM | Imagemagick: heap-buffer-overflow in coders/tiff.c |
| CVE-2023-3576 | 5.5 MEDIUM | Libtiff: memory leak in tiffcrop.c |
| CVE-2023-2422 | 5.5 MEDIUM | Keycloak: oauth client impersonation |
No comments yet