Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-5384

Опубликовано: 18 дек. 2023
Источник: nvd
CVSS3: 7.2
CVSS3: 2.7
EPSS Низкий

Описание

A flaw was found in Infinispan. When serializing the configuration for a cache to XML/JSON/YAML, which contains credentials (JDBC store with connection pooling, remote store), the credentials are returned in clear text as part of the configuration.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:redhat:data_grid:*:*:*:*:*:*:*:*
Версия до 8.4.6 (исключая)
Конфигурация 2
cpe:2.3:a:redhat:jboss_data_grid:-:*:*:*:text-only:*:*:*
Конфигурация 3
cpe:2.3:a:infinispan:infinispan:-:*:*:*:*:*:*:*

EPSS

Процентиль: 61%
0.00414
Низкий

7.2 High

CVSS3

2.7 Low

CVSS3

Дефекты

CWE-312
CWE-312

Связанные уязвимости

CVSS3: 7.2
redhat
около 2 лет назад

A flaw was found in Infinispan. When serializing the configuration for a cache to XML/JSON/YAML, which contains credentials (JDBC store with connection pooling, remote store), the credentials are returned in clear text as part of the configuration.

CVSS3: 2.7
github
около 2 лет назад

Infinispan caches credentials in clear text

EPSS

Процентиль: 61%
0.00414
Низкий

7.2 High

CVSS3

2.7 Low

CVSS3

Дефекты

CWE-312
CWE-312