7 Total advisories
7 Vulnerabilities
0 Malware
Dependency scanning
Check whether org.infinispan:infinispan-core is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
LOW 2.7
CVE-2023-5384
Infinispan caches credentials in clear text
HIGH 8.8
CVE-2016-0750
Infinispan: Deserialization of untrusted data in the Hot Rod Java client via automatic byte-array deserialization
HIGH 7.5
CVE-2019-10174
Use of Externally-Controlled Input to Select Classes or Code in Infinispan
CRITICAL 9.8
CVE-2019-10158
Improper implementation of the session fixation protection in Infinispan
MEDIUM 6.5
CVE-2020-25711
Improper Access Control in infinispan-server-runtime
HIGH 8.8
CVE-2018-1131
Deserialization of Untrusted Data in Infinispan
HIGH 8.8
CVE-2017-15089
Deserialization of Untrusted Data in Infinispan
Browse more Maven advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes