Back

MEDIUM

Infinispan: credentials returned from configuration as clear text

Published Dec 18, 2023

Description

A flaw was found in Infinispan. When serializing the configuration for a cache to XML/JSON/YAML, which contains credentials (JDBC store with connection pooling, remote store), the credentials are returned in clear text as part of the configuration.

Affected products

Remediation

Vendor solution

The issue's impact is limited because only users with administrator permissions can retrieve the cache configurations, and the recommended approach for connecting via JDBC is using the `datasource` configuration, which does not expose the database credentials.

Red Hat statement

Red Hat evaluated this vulnerability and this only affects Infinispan's server component, so Red Hat JBoss Enterprise Application Platform (EAP) and other tools that may run infinispan is not affected.

Red Hat mitigation

The issue's impact is limited because only users with administrator permissions can retrieve the cache configurations, and the recommended approach for connecting via JDBC is using the `datasource` configuration, which does not expose the database credentials.

Weaknesses (1)

References (13)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner redhat
Published Dec 18, 2023
Updated Nov 20, 2025
Reserved Oct 4, 2023

CISA Vulnrichment

Updated May 2, 2024

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

Severity Important
Public date Dec 6, 2023
Bugzilla 2242156

ENISA EUVD

Assigner redhat
Published Dec 18, 2023
Updated Nov 20, 2025