Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-5731

Опубликовано: 26 июн. 2025
Источник: redhat
CVSS3: 6.2
EPSS Низкий

Описание

A flaw was found in Infinispan CLI. A sensitive password, decoded from a Base64-encoded Kubernetes secret, is processed in plaintext and included in a command string that may expose the data in an error message when a command is not found.

Меры по смягчению последствий

Currently, no mitigation is available for this vulnerability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss Enterprise Application Platform 7infinispan-cli-clientAffected
Red Hat JBoss Enterprise Application Platform 8infinispan-cli-clientAffected
Red Hat JBoss Enterprise Application Platform Expansion Packinfinispan-cli-clientAffected
Red Hat Data Grid 8.5.4infinispan-cli-clientFixedRHSA-2025:1013001.07.2025

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-209
https://bugzilla.redhat.com/show_bug.cgi?id=2370429infinispan: Credential Leakage in Infinispan CLI

EPSS

Процентиль: 2%
0.00015
Низкий

6.2 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.2
nvd
20 дней назад

A flaw was found in Infinispan CLI. A sensitive password, decoded from a Base64-encoded Kubernetes secret, is processed in plaintext and included in a command string that may expose the data in an error message when a command is not found.

CVSS3: 6.2
github
20 дней назад

Infinispan CLI vulnerable to Generation of Error Message Containing Sensitive Information

EPSS

Процентиль: 2%
0.00015
Низкий

6.2 Medium

CVSS3