A flaw was found in Infinispan CLI. A sensitive password, decoded from a Base64-encoded Kubernetes secret, is processed in plaintext and included in a command string that may expose the data in an error message when a command is not found.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-19671 A flaw was found in Infinispan CLI. A sensitive password, decoded from a Base64-encoded Kubernetes secret, is processed in plaintext and included in a command string that may expose the data in an error message when a command is not found.
Github GHSA Github GHSA GHSA-cqm8-rg2p-jfcf Infinispan CLI vulnerable to Generation of Error Message Containing Sensitive Information
Fixes

Solution

No solution given by the vendor.


Workaround

Currently, no mitigation is available for this vulnerability.

History

Tue, 02 Sep 2025 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Infinispan
Infinispan infinispan
Redhat data Grid
Redhat jboss Enterprise Application Platform Expansion Pack
CPEs cpe:2.3:a:infinispan:infinispan:-:*:*:*:*:*:*:*
cpe:2.3:a:redhat:data_grid:8.5.4:*:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.0.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_enterprise_application_platform:8.0.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_enterprise_application_platform_expansion_pack:-:*:*:*:*:*:*:*
Vendors & Products Infinispan
Infinispan infinispan
Redhat data Grid
Redhat jboss Enterprise Application Platform Expansion Pack

Tue, 01 Jul 2025 20:15:00 +0000

Type Values Removed Values Added
References

Fri, 27 Jun 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 27 Jun 2025 00:30:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Thu, 26 Jun 2025 21:30:00 +0000

Type Values Removed Values Added
Description A flaw was found in Infinispan CLI. A sensitive password, decoded from a Base64-encoded Kubernetes secret, is processed in plaintext and included in a command string that may expose the data in an error message when a command is not found.
Title Infinispan: credential leakage in infinispan cli
First Time appeared Redhat
Redhat jboss Data Grid
Redhat jboss Enterprise Application Platform
Redhat jbosseapxp
Weaknesses CWE-209
CPEs cpe:/a:redhat:jboss_data_grid:8
cpe:/a:redhat:jboss_enterprise_application_platform:7
cpe:/a:redhat:jboss_enterprise_application_platform:8
cpe:/a:redhat:jbosseapxp
Vendors & Products Redhat
Redhat jboss Data Grid
Redhat jboss Enterprise Application Platform
Redhat jbosseapxp
References
Metrics cvssV3_1

{'score': 6.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2025-09-25T18:19:47.028Z

Reserved: 2025-06-05T13:48:09.202Z

Link: CVE-2025-5731

cve-icon Vulnrichment

Updated: 2025-06-27T13:13:29.867Z

cve-icon NVD

Status : Analyzed

Published: 2025-06-26T22:15:24.917

Modified: 2025-09-02T18:04:30.160

Link: CVE-2025-5731

cve-icon Redhat

Severity : Moderate

Publid Date: 2025-06-26T21:24:21Z

Links: CVE-2025-5731 - Bugzilla

cve-icon OpenCVE Enrichment

No data.