VDB
Sign up
MEDIUM5.5

GHSA-cqm8-rg2p-jfcf

Infinispan CLI vulnerable to Generation of Error Message Containing Sensitive Information

Details

A flaw was found in Infinispan CLI. A sensitive password, decoded from a Base64-encoded Kubernetes secret, is processed in plaintext and included in a command string that may expose the data in an error message when a command is not found.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/org.infinispan:infinispan-cli-client
Introduced in: 0

No fixed version published yet for org.infinispan:infinispan-cli-client (maven). Pin to a known-safe version or switch to an alternative.

References