CVE-2023-5384
18.12.2023, 14:15
A flaw was found in Infinispan. When serializing the configuration for a cache to XML/JSON/YAML, which contains credentials (JDBC store with connection pooling, remote store), the credentials are returned in clear text as part of the configuration.Enginsight
Vendor | Product | Version |
---|---|---|
redhat | data_grid | 𝑥 < 8.4.6 |
redhat | jboss_data_grid | - |
infinispan | infinispan | - |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References