CVE-2023-5384
published 2023-12-18CVE-2023-5384: A flaw was found in Infinispan. When serializing the configuration for a cache to XML/JSON/YAML, which contains credentials (JDBC store with connection…
PriorityP411low2.7CVSS 3.1
AVNACLPRHUINSUCLINAN
EPSS
0.54%
42.3th percentile
A flaw was found in Infinispan. When serializing the configuration for a cache to XML/JSON/YAML, which contains credentials (JDBC store with connection pooling, remote store), the credentials are returned in clear text as part of the configuration.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | data_grid | < 8.4.6 | 8.4.6 |
CVSS provenance
nvdv3.12.7LOWCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
vendor_redhat7.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
infinispan: Credentials returned from configuration as clear text
vendor_redhat·2023-12-06·CVSS 7.2
CVE-2023-5384 [HIGH] CWE-312 infinispan: Credentials returned from configuration as clear text
infinispan: Credentials returned from configuration as clear text
A flaw was found in Infinispan. When serializing the configuration for a cache to XML/JSON/YAML, which contains credentials (JDBC store with connection pooling, remote store), the credentials are returned in clear text as part of the configuration.
A flaw was found in Infinispan. When serializing the configuration for a cache to XML/JSON/YAML, which contains credentials (JDBC store with connection pooling, remote store), the credentials are returned in clear text as part of the configuration.
Statement: Red Hat evaluated this vulnerability and this only affects Infinispan's server component, so Red Hat JBoss Enterprise Application Platform (EAP) and other tools that may run infinispan is not affected.
Mitigation: The iss
GHSA
Infinispan caches credentials in clear text
ghsa·2023-12-28
CVE-2023-5384 [MEDIUM] CWE-312 Infinispan caches credentials in clear text
Infinispan caches credentials in clear text
A flaw was found in Infinispan. When serializing the configuration for a cache to XML/JSON/YAML, which contains credentials (JDBC store with connection pooling, remote store), the credentials are returned in clear text as part of the configuration.
OSV
Infinispan caches credentials in clear text
osv·2023-12-28
CVE-2023-5384 [MEDIUM] Infinispan caches credentials in clear text
Infinispan caches credentials in clear text
A flaw was found in Infinispan. When serializing the configuration for a cache to XML/JSON/YAML, which contains credentials (JDBC store with connection pooling, remote store), the credentials are returned in clear text as part of the configuration.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://access.redhat.com/errata/RHSA-2023:7676https://access.redhat.com/security/cve/CVE-2023-5384https://bugzilla.redhat.com/show_bug.cgi?id=2242156https://access.redhat.com/errata/RHSA-2023:7676https://access.redhat.com/security/cve/CVE-2023-5384https://bugzilla.redhat.com/show_bug.cgi?id=2242156https://security.netapp.com/advisory/ntap-20240125-0004/
2023-12-18
Published