It was found that the Hotrod client in Infinispan before 9.2.0.CR1 would unsafely read deserialized data on information from the cache. An authenticated attacker could inject a malicious object into the data cache and attain deserialization on the client, and possibly conduct further attacks.
{ "nvd_published_at": "2018-02-15T17:29:00Z", "github_reviewed_at": "2022-07-01T19:46:46Z", "severity": "HIGH", "github_reviewed": true, "cwe_ids": [ "CWE-502" ] }