{"id":"CVE-2017-15089","aliases":["GHSA-46r5-59fg-2fjc"],"url":"https://o3.security/vulnerability/CVE-2017-15089","summary":"Deserialization of Untrusted Data in Infinispan","details":"It was found that the Hotrod client in Infinispan before 9.2.0.CR1 would unsafely read deserialized data on information from the cache. An authenticated attacker could inject a malicious object into the data cache and attain deserialization on the client, and possibly conduct further attacks.","published":"2018-02-15T17:29:00.207Z","modified":"2026-07-08T11:49:12.987364Z","cvss":{"score":8.8,"severity":"HIGH","vector":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.infinispan:infinispan-core","fixedVersion":"9.2.0.CR1"}],"fix":{"url":"https://github.com/infinispan/infinispan/pull/5639","label":"infinispan/infinispan#5639"},"references":[{"type":"ADVISORY","url":"http://www.securitytracker.com/id/1040360"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2018:0294"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2018:0478"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2018:0479"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2018:0480"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2018:0481"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2018:0501"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2019:1326"},{"type":"FIX","url":"https://github.com/infinispan/infinispan/pull/5639"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T11:49:12.987364Z"}}