Description
A flaw was found in Infinispan CLI. A sensitive password, decoded from a Base64-encoded Kubernetes secret, is processed in plaintext and included in a command string that may expose the data in an error message when a command is not found.
Scores
CVSS v3
5.5
EPSS
0.0008
EPSS Percentile
23.7%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-209
Status
published
Products (6)
infinispan/infinispan
org.infinispan/infinispan-cli-client
0Maven
redhat/data_grid
8.5.4
redhat/jboss_enterprise_application_platform
7.0.0
redhat/jboss_enterprise_application_platform
8.0.0
redhat/jboss_enterprise_application_platform_expansion_pack
Published
Jun 26, 2025
Tracked Since
Feb 18, 2026