A flaw was found in Infinispan, when using JGroups with JDBC_PING. This issue occurs when an application inadvertently exposes sensitive information, such as configuration details or credentials, through logging mechanisms. This exposure can lead to unauthorized access and exploitation by malicious actors.
Metrics
Affected Vendors & Products
References
History
Wed, 12 Mar 2025 03:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Tue, 28 Jan 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 28 Jan 2025 09:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Title | org.infinispan-infinispan-parent: Exposure of Sensitive Information in Application Logs | Org.infinispan-infinispan-parent: exposure of sensitive information in application logs |
First Time appeared |
Redhat
Redhat jboss Data Grid |
|
CPEs | cpe:/a:redhat:jboss_data_grid:8 | |
Vendors & Products |
Redhat
Redhat jboss Data Grid |
|
References |
|
Tue, 28 Jan 2025 03:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A flaw was found in Infinispan, when using JGroups with JDBC_PING. This issue occurs when an application inadvertently exposes sensitive information, such as configuration details or credentials, through logging mechanisms. This exposure can lead to unauthorized access and exploitation by malicious actors. | |
Title | org.infinispan-infinispan-parent: Exposure of Sensitive Information in Application Logs | |
Weaknesses | CWE-532 | |
References |
| |
Metrics |
threat_severity
|
cvssV3_1
|

Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2025-03-14T10:24:29.251Z
Reserved: 2025-01-27T11:46:29.978Z
Link: CVE-2025-0736

Updated: 2025-01-28T14:38:29.907Z

Status : Awaiting Analysis
Published: 2025-01-28T09:15:09.543
Modified: 2025-03-12T04:15:16.120
Link: CVE-2025-0736
