Uploaded image for project: 'Red Hat Data Grid'
  1. Red Hat Data Grid
  2. JDG-7649

CVE-2025-5731 infinispan-cli-client: Credential Leakage in Infinispan CLI [jdg-8]

XMLWordPrintable

    • False
    • Hide

      None

      Show
      None
    • False
    • Upstream
    • CVE-2025-5731
    • 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
    • CWE-209
    • infinispan-cli-client
    • infinispan
    • False
    • Moderate

      Security Tracking Issue

      Do not make this issue public.

      Flaw:


      Credential Leakage in Infinispan CLI
      https://bugzilla.redhat.com/show_bug.cgi?id=2370429

      A flaw was found in Infinispan CLI. A sensitive password, decoded from a Base64-encoded Kubernetes secret is processed in plaintext and included in a command string that may expose the data in an error message when a command is not found.

      ~~~

      Tracker accuracy feedback form: https://docs.google.com/forms/d/e/1FAIpQLSfa6zTaEGohRdiIqGVAvWTSAL0kpO_DkkEICuIHzQHFwmKswg/viewform

              ttarrant@redhat.com Tristan Tarrant
              rhn-support-pdelbell Patrick Del Bello
              Pavel Drobek Pavel Drobek
              Alan Field, Paramvir Jindal, Pavel Drobek, Priyanka Minz, Tristan Tarrant
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated:
                Resolved: