First published: Mon Jan 27 2025(Updated: )
A flaw was found in Infinispan, when using JGroups with JDBC_PING. This issue occurs when an application inadvertently exposes sensitive information, such as configuration details or credentials, through logging mechanisms. This exposure can lead to unauthorized access and exploitation by malicious actors.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Infinispan Infinispan | ||
maven/org.infinispan:infinispan-parent | <=15.1.4.Final |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-0736 has been classified as a medium severity vulnerability due to the risk of exposing sensitive information.
To fix CVE-2025-0736, update your Infinispan to a version higher than 15.1.4.Final or ensure sensitive information is not logged.
CVE-2025-0736 affects Infinispan versions up to and including 15.1.4.Final when using JDBC_PING with JGroups.
CVE-2025-0736 can inadvertently expose sensitive information such as configuration details or credentials through logging.
The risks associated with CVE-2025-0736 include unauthorized access and exploitation of sensitive information.