Description


A flaw was found in Infinispan CLI. A sensitive password, decoded from a Base64-encoded Kubernetes secret, is processed in plaintext and included in a command string that may expose the data in an error message when a command is not found.

Related CPE's



a

redhat

jboss_enterprise_application_platform

2


Weaknesses



CWE-209

CVSS impact metrics


CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

6.2 · Medium

  • CVSS V3.1

  • CVSS V3.0

  • CVSS V2.0

Information


Source identifier

[email protected]

Vulnerability status

Analyzed

Published

2025-06-26T22:15:24.917

5 months ago

Last modified

2025-09-02T18:04:30.160

3 months ago