Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-5731

Опубликовано: 26 июн. 2025
Источник: redhat
CVSS3: 6.2
EPSS Низкий

Описание

A flaw was found in Infinispan CLI. A sensitive password, decoded from a Base64-encoded Kubernetes secret, is processed in plaintext and included in a command string that may expose the data in an error message when a command is not found.

Отчет

Red Hat JBoss Enterprise Application Platform are not affected by this vulnerability. This flaw is rated as a Moderate vulnerability rather than an Important one because it requires specific conditions to be met for sensitive data exposure to occur. The password is only revealed if a user executes an invalid CLI command after including the decoded secret in the command string, which is a user-side misuse rather than a flaw in the core authentication or encryption logic of Infinispan. Additionally, the exposure is local to the terminal or logs and does not involve unauthorized remote access, privilege escalation, or systemic compromise.

Меры по смягчению последствий

Currently, no mitigation is available for this vulnerability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss Enterprise Application Platform 7infinispan-cli-clientNot affected
Red Hat JBoss Enterprise Application Platform 8infinispan-cli-clientNot affected
Red Hat JBoss Enterprise Application Platform Expansion Packinfinispan-cli-clientNot affected
Red Hat Data Grid 8.5.4infinispan-cli-clientFixedRHSA-2025:1013001.07.2025

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-209
https://bugzilla.redhat.com/show_bug.cgi?id=2370429infinispan: Credential Leakage in Infinispan CLI

EPSS

Процентиль: 3%
0.00017
Низкий

6.2 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.2
nvd
6 месяцев назад

A flaw was found in Infinispan CLI. A sensitive password, decoded from a Base64-encoded Kubernetes secret, is processed in plaintext and included in a command string that may expose the data in an error message when a command is not found.

CVSS3: 6.2
github
6 месяцев назад

Infinispan CLI vulnerable to Generation of Error Message Containing Sensitive Information

EPSS

Процентиль: 3%
0.00017
Низкий

6.2 Medium

CVSS3