A flaw was found in Infinispan CLI. A sensitive password, decoded from a Base64-encoded Kubernetes secret, is processed in plaintext and included in a command string that may expose the data in an error message when a command is not found.
References
| Link | Resource |
|---|---|
| https://access.redhat.com/errata/RHSA-2025:10130 | Third Party Advisory |
| https://access.redhat.com/security/cve/CVE-2025-5731 | Third Party Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2370429 | Issue Tracking Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
No history.
Information
Published : 2025-06-26 22:15
Updated : 2025-09-02 18:04
NVD link : CVE-2025-5731
Mitre link : CVE-2025-5731
CVE.ORG link : CVE-2025-5731
JSON object : View
Products Affected
infinispan
- infinispan
redhat
- data_grid
- jboss_enterprise_application_platform
- jboss_enterprise_application_platform_expansion_pack
CWE
CWE-209
Generation of Error Message Containing Sensitive Information
