Critical severity9.8NVD Advisory· Published Jan 2, 2020· Updated Jun 17, 2026
CVE-2019-10158
CVE-2019-10158
Description
A flaw was found in Infinispan through version 9.4.14.Final. An improper implementation of the session fixation protection in the Spring Session integration can result in incorrect session handling.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.infinispan:infinispan-coreMaven | < 9.4.15.Final | 9.4.15.Final |
Affected products
4- Red Hat/infinispanv5Range: n/a
Patches
Vulnerability mechanics
References
10- bugzilla.redhat.com/show_bug.cginvdIssue TrackingPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-6x3v-rw2q-9gx7ghsaADVISORY
- github.com/infinispan/infinispan/pull/6960nvdThird Party AdvisoryWEB
- github.com/infinispan/infinispan/pull/7025nvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2019-10158ghsaADVISORY
- github.com/infinispan/infinispan/commit/4b381c5910265972ccaabefbdbd16a2b929f6b72ghsaWEB
- github.com/infinispan/infinispan/commits/9.4.15.FinalghsaWEB
- github.com/infinispan/infinispan/pull/7043ghsaWEB
- security.netapp.com/advisory/ntap-20231227-0009ghsaWEB
- security.netapp.com/advisory/ntap-20231227-0009/nvd
News mentions
0No linked articles in our index yet.