CVE-2023-5384

A flaw was found in Infinispan. When serializing the configuration for a cache to XML/JSON/YAML, which contains credentials (JDBC store with connection pooling, remote store), the credentials are returned in clear text as part of the configuration.
Configurations

Configuration 1 (hide)

cpe:2.3:a:redhat:data_grid:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:a:redhat:jboss_data_grid:-:*:*:*:text-only:*:*:*

Configuration 3 (hide)

cpe:2.3:a:infinispan:infinispan:-:*:*:*:*:*:*:*

History

21 Nov 2024, 08:41

Type Values Removed Values Added
References
  • () https://security.netapp.com/advisory/ntap-20240125-0004/ -
References () https://access.redhat.com/errata/RHSA-2023:7676 - Vendor Advisory () https://access.redhat.com/errata/RHSA-2023:7676 - Vendor Advisory
References () https://access.redhat.com/security/cve/CVE-2023-5384 - Vendor Advisory () https://access.redhat.com/security/cve/CVE-2023-5384 - Vendor Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=2242156 - Issue Tracking () https://bugzilla.redhat.com/show_bug.cgi?id=2242156 - Issue Tracking
CVSS v2 : unknown
v3 : 2.7
v2 : unknown
v3 : 7.2

16 Sep 2024, 16:15

Type Values Removed Values Added
References
  • {'url': 'https://security.netapp.com/advisory/ntap-20240125-0004/', 'source': 'secalert@redhat.com'}

25 Jan 2024, 14:15

Type Values Removed Values Added
References
  • () https://security.netapp.com/advisory/ntap-20240125-0004/ -

28 Dec 2023, 18:16

Type Values Removed Values Added
Summary
  • (es) Se encontró una falla en Infinispan. Al serializar la configuración de una caché en XML/JSON/YAML, que contiene credenciales (almacén JDBC con agrupación de conexiones, almacén remoto), las credenciales se devuelven en texto plano como parte de la configuración.
First Time Infinispan infinispan
Infinispan
Redhat
Redhat jboss Data Grid
Redhat data Grid
References () https://access.redhat.com/errata/RHSA-2023:7676 - () https://access.redhat.com/errata/RHSA-2023:7676 - Vendor Advisory
References () https://access.redhat.com/security/cve/CVE-2023-5384 - () https://access.redhat.com/security/cve/CVE-2023-5384 - Vendor Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=2242156 - () https://bugzilla.redhat.com/show_bug.cgi?id=2242156 - Issue Tracking
CPE cpe:2.3:a:infinispan:infinispan:-:*:*:*:*:*:*:*
cpe:2.3:a:redhat:data_grid:*:*:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_data_grid:-:*:*:*:text-only:*:*:*
CVSS v2 : unknown
v3 : 7.2
v2 : unknown
v3 : 2.7

18 Dec 2023, 15:04

Type Values Removed Values Added
New CVE

Information

Published : 2023-12-18 14:15

Updated : 2024-11-21 08:41


NVD link : CVE-2023-5384

Mitre link : CVE-2023-5384

CVE.ORG link : CVE-2023-5384


JSON object : View

Products Affected

redhat

  • data_grid
  • jboss_data_grid

infinispan

  • infinispan
CWE
CWE-312

Cleartext Storage of Sensitive Information