No analysis available yet.
Vendor Workaround
The issue's impact is limited because only users with administrator permissions can retrieve the cache configurations, and the recommended approach for connecting via JDBC is using the `datasource` configuration, which does not expose the database credentials.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-3210 | A flaw was found in Infinispan. When serializing the configuration for a cache to XML/JSON/YAML, which contains credentials (JDBC store with connection pooling, remote store), the credentials are returned in clear text as part of the configuration. |
Github GHSA |
GHSA-gg57-587f-h5v6 | Infinispan caches credentials in clear text |
Fri, 22 Nov 2024 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 08 Oct 2024 03:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2025-11-20T07:07:36.736Z
Reserved: 2023-10-04T16:12:42.727Z
Link: CVE-2023-5384
Updated: 2024-08-02T07:59:44.661Z
Status : Modified
Published: 2023-12-18T14:15:11.360
Modified: 2024-11-21T08:41:39.760
Link: CVE-2023-5384
OpenCVE Enrichment
No data.
EUVD
Github GHSA