MEDIUM5.5
GHSA-cqm8-rg2p-jfcf
Infinispan CLI vulnerable to Generation of Error Message Containing Sensitive Information
Details
A flaw was found in Infinispan CLI. A sensitive password, decoded from a Base64-encoded Kubernetes secret, is processed in plaintext and included in a command string that may expose the data in an error message when a command is not found.
Are you affected?
Enter the version of the package you're using.
Affected packages
Maven/org.infinispan:infinispan-cli-client
Introduced in:
0No fixed version published yet for org.infinispan:infinispan-cli-client (maven). Pin to a known-safe version or switch to an alternative.