CVE-2023-5384: Infinispan: credentials returned from configuration as clear text
A flaw was found in Infinispan. When serializing the configuration for a cache to XML/JSON/YAML, which contains credentials (JDBC store with connection pooling, remote store), the credentials are returned in clear text as part of the configuration.
Other sources
When serializing the configuration for a cache to XML/JSON/YAML which contains credentials (JDBC store with connection pooling, Remote store) the credentials are returned in clear text as part of the configuration.
The issue's impact is limited because only users with the ADMIN permission can retrieve the cache configurations, and the recommended approach for connecting via JDBC is using the datasource configuration which does not expose the database credentials.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-5384?
CVE-2023-5384 has been classified with a high severity level due to the exposure of sensitive credentials in clear text.
How do I fix CVE-2023-5384?
To remediate CVE-2023-5384, you should upgrade to versions 14.0.25.Final or 15.0.0.Dev07 of the affected Infinispan packages.
Which Infinispan versions are affected by CVE-2023-5384?
CVE-2023-5384 affects versions prior to 14.0.25.Final and versions between 15.0.0.Dev01 and 15.0.0.Dev07.
What specific packages are vulnerable due to CVE-2023-5384?
The vulnerable packages include infinispan-cachestore-jdbc, infinispan-cachestore-sql, infinispan-cachestore-remote, infinispan-client-hotrod, and others.
Is CVE-2023-5384 applicable to Red Hat Data Grid users?
Yes, CVE-2023-5384 affects Red Hat Data Grid versions prior to 8.4.6.