CVE-2025-5731
published 2025-06-26CVE-2025-5731: A flaw was found in Infinispan CLI. A sensitive password, decoded from a Base64-encoded Kubernetes secret, is processed in plaintext and included in a command…
PriorityP424medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.14%
3.8th percentile
A flaw was found in Infinispan CLI. A sensitive password, decoded from a Base64-encoded Kubernetes secret, is processed in plaintext and included in a command string that may expose the data in an error message when a command is not found.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| msrc | azl3_mozjs_102.15.1-1_on_azure_linux_3.0 | — | — |
| red_hat | infinispan | < 15.2.5 | 15.2.5 |
| redhat | data_grid | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
vendor_msrc9.8CRITICAL
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
infinispan: Credential Leakage in Infinispan CLI
vendor_redhat·2025-06-26·CVSS 5.5
CVE-2025-5731 [MEDIUM] CWE-209 infinispan: Credential Leakage in Infinispan CLI
infinispan: Credential Leakage in Infinispan CLI
A flaw was found in Infinispan CLI. A sensitive password, decoded from a Base64-encoded Kubernetes secret, is processed in plaintext and included in a command string that may expose the data in an error message when a command is not found.
A flaw was found in Infinispan CLI. A sensitive password, decoded from a Base64-encoded Kubernetes secret, is processed in plaintext and included in a command string that may expose the data in an error message when a command is not found.
Statement: Red Hat JBoss Enterprise Application Platform are not affected by this vulnerability.
This flaw is rated as a Moderate vulnerability rather than an Important one because it requires specific conditions to be met for sensitive data exposure to occur. The pas
Microsoft
Memory safety bugs present in Firefox 118. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
vendor_msrc·2023-10-10·CVSS 9.8
CVE-2023-5731 [CRITICAL] CWE-787 Memory safety bugs present in Firefox 118. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
Memory safety bugs present in Firefox 118. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is i
OSV
Infinispan CLI vulnerable to Generation of Error Message Containing Sensitive Information
osv·2025-06-27
CVE-2025-5731 [MEDIUM] Infinispan CLI vulnerable to Generation of Error Message Containing Sensitive Information
Infinispan CLI vulnerable to Generation of Error Message Containing Sensitive Information
A flaw was found in Infinispan CLI. A sensitive password, decoded from a Base64-encoded Kubernetes secret, is processed in plaintext and included in a command string that may expose the data in an error message when a command is not found.
GHSA
Infinispan CLI vulnerable to Generation of Error Message Containing Sensitive Information
ghsa·2025-06-27
CVE-2025-5731 [MEDIUM] CWE-209 Infinispan CLI vulnerable to Generation of Error Message Containing Sensitive Information
Infinispan CLI vulnerable to Generation of Error Message Containing Sensitive Information
A flaw was found in Infinispan CLI. A sensitive password, decoded from a Base64-encoded Kubernetes secret, is processed in plaintext and included in a command string that may expose the data in an error message when a command is not found.
No detection rules found.
No public exploits indexed.
2025-06-26
Published