A flaw was found in Infinispan. When serializing the configuration for a cache to XML/JSON/YAML, which contains credentials (JDBC store with connection pooling, remote store), the credentials are returned in clear text as part of the configuration.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HInfinispan
APPInfinispanall versionsRed Hat Data Grid
APPRedhat< 8.4.6Red Hat Jboss Data Grid
APPRedhatall versions
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
References
Related vulnerabilities
CVE-2025-12543CRITICAL9.6PL ✓same product
Brak walidacji nagłówka Host w serwerze Undertow HTTP
CVE-2021-31917CRITICAL9.8PL ✓same product
Pominięcie uwierzytelnienia REST w Red Hat DataGrid i Infinispan
CVE-2019-14887CRITICAL9.1PL ✓same product
Wildfly: ignorowanie 'enabled-protocols' umożliwia TLS downgrade
CVE-2019-14892CRITICAL9.8PL ✓same product
RCE poprzez deserializację JNDI w jackson-databind (commons-configuration)
CVE-2019-10158CRITICAL9.8PL ✓same product
Nieprawidłowa ochrona przed session fixation w Infinispan (Spring Session)