Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-5384

Опубликовано: 06 дек. 2023
Источник: redhat
CVSS3: 7.2
EPSS Низкий

Описание

A flaw was found in Infinispan. When serializing the configuration for a cache to XML/JSON/YAML, which contains credentials (JDBC store with connection pooling, remote store), the credentials are returned in clear text as part of the configuration.

Отчет

Red Hat evaluated this vulnerability and this only affects Infinispan's server component, so Red Hat JBoss Enterprise Application Platform (EAP) and other tools that may run infinispan is not affected.

Меры по смягчению последствий

The issue's impact is limited because only users with administrator permissions can retrieve the cache configurations, and the recommended approach for connecting via JDBC is using the datasource configuration, which does not expose the database credentials.

Дополнительная информация

Статус:

Important
Дефект:
CWE-312
https://bugzilla.redhat.com/show_bug.cgi?id=2242156infinispan: Credentials returned from configuration as clear text

EPSS

Процентиль: 67%
0.00527
Низкий

7.2 High

CVSS3

Связанные уязвимости

CVSS3: 7.2
nvd
около 2 лет назад

A flaw was found in Infinispan. When serializing the configuration for a cache to XML/JSON/YAML, which contains credentials (JDBC store with connection pooling, remote store), the credentials are returned in clear text as part of the configuration.

CVSS3: 2.7
github
около 2 лет назад

Infinispan caches credentials in clear text

EPSS

Процентиль: 67%
0.00527
Низкий

7.2 High

CVSS3