A flaw was found in Infinispan. When serializing the configuration for a cache to XML/JSON/YAML, which contains credentials (JDBC store with connection pooling, remote store), the credentials are returned in clear text as part of the configuration.
Metrics
Affected Vendors & Products
References
History
Tue, 08 Oct 2024 03:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Metrics |
ssvc
|
MITRE
Status: PUBLISHED
Assigner: redhat
Published: 2023-12-18T13:43:08.728Z
Updated: 2024-10-08T01:56:02.931Z
Reserved: 2023-10-04T16:12:42.727Z
Link: CVE-2023-5384
Vulnrichment
Updated: 2024-08-02T07:59:44.661Z
NVD
Status : Modified
Published: 2023-12-18T14:15:11.360
Modified: 2024-09-16T16:15:09.150
Link: CVE-2023-5384
Redhat