Infinispan: credentials returned from configuration as clear text
Published Dec 18, 2023
5.1
MEDIUMCVSS 4.0
EPSS 0.54%
Description
A flaw was found in Infinispan. When serializing the configuration for a cache to XML/JSON/YAML, which contains credentials (JDBC store with connection pooling, remote store), the credentials are returned in clear text as part of the configuration.
Affected products
No data.
Configuration 2
- n/a
Configuration 3
- n/a
No data.
Red Hat Data Grid 8.4.6
infinispan
Fixed · RHSA-2023:7676
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Data Grid 8.4.6 | infinispan | Fixed | RHSA-2023:7676 |
No package ranges for this CVE.
Remediation
Vendor solution
The issue's impact is limited because only users with administrator permissions can retrieve the cache configurations, and the recommended approach for connecting via JDBC is using the `datasource` configuration, which does not expose the database credentials.
Red Hat statement
Red Hat evaluated this vulnerability and this only affects Infinispan's server component, so Red Hat JBoss Enterprise Application Platform (EAP) and other tools that may run infinispan is not affected.
Red Hat mitigation
The issue's impact is limited because only users with administrator permissions can retrieve the cache configurations, and the recommended approach for connecting via JDBC is using the `datasource` configuration, which does not expose the database credentials.
References (13)
- https://access.redhat.com/errata/RHSA-2023:7676 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/security/cve/CVE-2023-5384 vdb-entryx_refsource_REDHATVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2242156 issue-trackingx_refsource_REDHATIssue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-3210 Advisory
- https://github.com/advisories/GHSA-gg57-587f-h5v6 Advisory
- https://github.com/infinispan/infinispan/commit/7140fc9b026ec55786c1aa78bb3cd8bf951fad47
- https://github.com/infinispan/infinispan/commit/fd3e18ec3b1a4e7fcfd79392f5bf78792a2b8c61
- https://github.com/infinispan/infinispan/pull/11555
- https://github.com/infinispan/infinispan/pull/11995
- https://issues.redhat.com/browse/ISPN-15202
- https://nvd.nist.gov/vuln/detail/CVE-2023-5384
- https://security.netapp.com/advisory/ntap-20240125-0004
- https://www.cve.org/CVERecord?id=CVE-2023-5384
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2023:7676 | vendor-advisoryx_refsource_REDHATVendor Advisory | |
| https://access.redhat.com/security/cve/CVE-2023-5384 | vdb-entryx_refsource_REDHATVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2242156 | issue-trackingx_refsource_REDHATIssue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-3210 | Advisory | |
| https://github.com/advisories/GHSA-gg57-587f-h5v6 | Advisory | |
| https://github.com/infinispan/infinispan/commit/7140fc9b026ec55786c1aa78bb3cd8bf951fad47 | ||
| https://github.com/infinispan/infinispan/commit/fd3e18ec3b1a4e7fcfd79392f5bf78792a2b8c61 | ||
| https://github.com/infinispan/infinispan/pull/11555 | ||
| https://github.com/infinispan/infinispan/pull/11995 | ||
| https://issues.redhat.com/browse/ISPN-15202 | ||
| https://nvd.nist.gov/vuln/detail/CVE-2023-5384 | ||
| https://security.netapp.com/advisory/ntap-20240125-0004 | ||
| https://www.cve.org/CVERecord?id=CVE-2023-5384 |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub