CVE-2019-10174
Use of Externally-Controlled Input to Select Classes or Code in Infinispan
7.5
HIGH
CVSS 3.1
EPSS 3.1%
Description
A vulnerability was found in Infinispan such that the invokeAccessibly method from the public class ReflectionUtil allows any application class to invoke private methods in any class with Infinispan's privileges. The attacker can use reflection to introduce new, malicious behavior into the application.
How to fix CVE-2019-10174
To remediate CVE-2019-10174, upgrade the affected package to a fixed version below.
- —upgrade to 8.2.12.Final or later
Is CVE-2019-10174 being exploited?
Low — EPSS is 3.1%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 8.2.12.Final
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |