Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cqm8-rg2p-jfcf

Опубликовано: 27 июн. 2025
Источник: github
Github: Прошло ревью
CVSS3: 6.2

Описание

Infinispan CLI vulnerable to Generation of Error Message Containing Sensitive Information

A flaw was found in Infinispan CLI. A sensitive password, decoded from a Base64-encoded Kubernetes secret, is processed in plaintext and included in a command string that may expose the data in an error message when a command is not found.

Пакеты

Наименование

org.infinispan:infinispan-cli-client

maven
Затронутые версииВерсия исправления

<= 16.0.0.Dev01

Отсутствует

EPSS

Процентиль: 2%
0.00015
Низкий

6.2 Medium

CVSS3

Дефекты

CWE-209

Связанные уязвимости

CVSS3: 6.2
redhat
20 дней назад

A flaw was found in Infinispan CLI. A sensitive password, decoded from a Base64-encoded Kubernetes secret, is processed in plaintext and included in a command string that may expose the data in an error message when a command is not found.

CVSS3: 6.2
nvd
20 дней назад

A flaw was found in Infinispan CLI. A sensitive password, decoded from a Base64-encoded Kubernetes secret, is processed in plaintext and included in a command string that may expose the data in an error message when a command is not found.

EPSS

Процентиль: 2%
0.00015
Низкий

6.2 Medium

CVSS3

Дефекты

CWE-209