ZeroHour

CVE-2023-5384

CVSS 3.1
2.7 low
EPSS
<1%p44
Published
()
Modified
Description

A flaw was found in Infinispan. When serializing the configuration for a cache to XML/JSON/YAML, which contains credentials (JDBC store with connection pooling, remote store), the credentials are returned in clear text as part of the configuration.

Vendors
redhatinfinispan
Products
data grid, jboss data grid, infinispan
Weakness
CWE-312
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.