A flaw was found in Infinispan. When serializing the configuration for a cache to XML/JSON/YAML, which contains credentials (JDBC store with connection pooling, remote store), the credentials are returned in clear text as part of the configuration.
Metrics
Affected Vendors & Products
References
History
Fri, 22 Nov 2024 12:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Tue, 08 Oct 2024 03:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Metrics |
ssvc
|
MITRE
Status: PUBLISHED
Assigner: redhat
Published: 2023-12-18T13:43:08.728Z
Updated: 2024-11-23T03:22:41.960Z
Reserved: 2023-10-04T16:12:42.727Z
Link: CVE-2023-5384
Vulnrichment
Updated: 2024-08-02T07:59:44.661Z
NVD
Status : Modified
Published: 2023-12-18T14:15:11.360
Modified: 2024-11-21T08:41:39.760
Link: CVE-2023-5384
Redhat