Red Hat Infinispan vulnerabilities
3 known vulnerabilities affecting red_hat/infinispan.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2025-5731MEDIUMCVSS 5.5fixed in 15.2.52025-06-26
CVE-2025-5731 [MEDIUM] CWE-209 CVE-2025-5731: A flaw was found in Infinispan CLI. A sensitive password, decoded from a Base64-encoded Kubernetes s
A flaw was found in Infinispan CLI. A sensitive password, decoded from a Base64-encoded Kubernetes secret, is processed in plaintext and included in a command string that may expose the data in an error message when a command is not found.
cvelistv5nvd
CVE-2019-10158CRITICALCVSS 9.8vn/a2020-01-02
CVE-2019-10158 [CRITICAL] CWE-384 CVE-2019-10158: A flaw was found in Infinispan through version 9.4.14.Final. An improper implementation of the sessi
A flaw was found in Infinispan through version 9.4.14.Final. An improper implementation of the session fixation protection in the Spring Session integration can result in incorrect session handling.
cvelistv5nvd
CVE-2016-0750HIGHCVSS 8.8v9.1.0.Final2018-09-11
CVE-2016-0750 [MEDIUM] CWE-138 CVE-2016-0750: The hotrod java client in infinispan before 9.1.0.Final automatically deserializes bytearray message
The hotrod java client in infinispan before 9.1.0.Final automatically deserializes bytearray message contents in certain events. A malicious user could exploit this flaw by injecting a specially-crafted serialized object to attain remote code execution or conduct other attacks.
cvelistv5nvd