A flaw was found in Infinispan, when using JGroups with JDBC_PING. This issue occurs when an application inadvertently exposes sensitive information, such as configuration details or credentials, through logging mechanisms. This exposure can lead to unauthorized access and exploitation by malicious actors.
History

Tue, 28 Jan 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 28 Jan 2025 09:15:00 +0000

Type Values Removed Values Added
Title org.infinispan-infinispan-parent: Exposure of Sensitive Information in Application Logs Org.infinispan-infinispan-parent: exposure of sensitive information in application logs
First Time appeared Redhat
Redhat jboss Data Grid
CPEs cpe:/a:redhat:jboss_data_grid:8
Vendors & Products Redhat
Redhat jboss Data Grid
References

Tue, 28 Jan 2025 03:15:00 +0000

Type Values Removed Values Added
Description A flaw was found in Infinispan, when using JGroups with JDBC_PING. This issue occurs when an application inadvertently exposes sensitive information, such as configuration details or credentials, through logging mechanisms. This exposure can lead to unauthorized access and exploitation by malicious actors.
Title org.infinispan-infinispan-parent: Exposure of Sensitive Information in Application Logs
Weaknesses CWE-532
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

threat_severity

Moderate


cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2025-01-28T14:38:34.306Z

Reserved: 2025-01-27T11:46:29.978Z

Link: CVE-2025-0736

cve-icon Vulnrichment

Updated: 2025-01-28T14:38:29.907Z

cve-icon NVD

Status : Received

Published: 2025-01-28T09:15:09.543

Modified: 2025-01-28T09:15:09.543

Link: CVE-2025-0736

cve-icon Redhat

Severity : Moderate

Publid Date: 2025-01-27T00:00:00Z

Links: CVE-2025-0736 - Bugzilla