A flaw was found in Infinispan. When serializing the configuration for a cache to XML/JSON/YAML, which contains credentials (JDBC store with connection pooling, remote store), the credentials are returned in clear text as part of the configuration.
References
Link | Resource |
---|---|
https://access.redhat.com/errata/RHSA-2023:7676 | Vendor Advisory |
https://access.redhat.com/security/cve/CVE-2023-5384 | Vendor Advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=2242156 | Issue Tracking |
https://security.netapp.com/advisory/ntap-20240125-0004/ |
Configurations
History
No history.
Information
Published : 2023-12-18 14:15
Updated : 2024-01-25 14:15
NVD link : CVE-2023-5384
Mitre link : CVE-2023-5384
CVE.ORG link : CVE-2023-5384
JSON object : View
Products Affected
redhat
- jboss_data_grid
- data_grid
infinispan
- infinispan
CWE
CWE-312
Cleartext Storage of Sensitive Information