A flaw was found in Infinispan. When serializing the configuration for a cache to XML/JSON/YAML, which contains credentials (JDBC store with connection pooling, remote store), the credentials are returned in clear text as part of the configuration.
2023-12-18T14:15:11.360
2024-11-21T08:41:39.760
Modified
CVSSv3.1: 7.2 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | redhat | data_grid | < 8.4.6 | Yes |
Application | redhat | jboss_data_grid | - | Yes |
Application | infinispan | infinispan | - | Yes |