Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-5731


A flaw was found in Infinispan CLI. A sensitive password, decoded from a Base64-encoded Kubernetes secret, is processed in plaintext and included in a command string that may expose the data in an error message when a command is not found.


Published

2025-06-26T22:15:24.917

Last Modified

2025-09-02T18:04:30.160

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 6.2 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-209

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application redhat data_grid 8.5.4 Yes
Application redhat jboss_enterprise_application_platform 7.0.0 Yes
Application redhat jboss_enterprise_application_platform 8.0.0 Yes
Application redhat jboss_enterprise_application_platform_expansion_pack - Yes
Application infinispan infinispan - Yes

References