CVE-2025-5731

Severity
5.5MEDIUM
EPSS
0.0%
top 91.34%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 26
Latest updateJun 27

Description

A flaw was found in Infinispan CLI. A sensitive password, decoded from a Base64-encoded Kubernetes secret, is processed in plaintext and included in a command string that may expose the data in an error message when a command is not found.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages4 packages

🔴Vulnerability Details

3
OSV
Infinispan CLI vulnerable to Generation of Error Message Containing Sensitive Information2025-06-27
GHSA
Infinispan CLI vulnerable to Generation of Error Message Containing Sensitive Information2025-06-27
CVEList
Infinispan: credential leakage in infinispan cli2025-06-26

📋Vendor Advisories

2
Red Hat
infinispan: Credential Leakage in Infinispan CLI2025-06-26
Microsoft
Memory safety bugs present in Firefox 118. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.2023-10-10
CVE-2025-5731 (MEDIUM CVSS 5.5) | A flaw was found in Infinispan CLI | cvebase.io