CVE Vulnerabilities

CVE-2025-0736

Insertion of Sensitive Information into Log File

Published: Jan 28, 2025 | Modified: Mar 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
5.5 MODERATE
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Ubuntu

A flaw was found in Infinispan, when using JGroups with JDBC_PING. This issue occurs when an application inadvertently exposes sensitive information, such as configuration details or credentials, through logging mechanisms. This exposure can lead to unauthorized access and exploitation by malicious actors.

Weakness

The product writes sensitive information to a log file.

Affected Software

Name Vendor Start Version End Version
Red Hat Data Grid RedHat org.infinispan-infinispan-parent *

Potential Mitigations

References