First published: Mon Jan 27 2025(Updated: )
A vulnerability has been identified in Infinispan where sensitive credentials, such as database usernames and passwords, are logged when using JGroups with JDBC_PING. If a misconfiguration (such as an unresolved external_addr) occurs, the logging mechanism records connection details, including credentials, in plaintext. This issue can lead to credential exposure, potentially allowing unauthorized access if logs are accessible to low-privileged users or attackers.
Affected Software | Affected Version | How to fix |
---|---|---|
Infinispan |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-2342233 is considered high due to the potential exposure of sensitive credentials.
To fix REDHAT-BUG-2342233, ensure that JGroups is properly configured to avoid misconfigurations that lead to logging sensitive information.
The risks associated with REDHAT-BUG-2342233 include unauthorized access to database credentials and other sensitive information through logs.
The vulnerability REDHAT-BUG-2342233 affects certain versions of Infinispan when using JGroups with JDBC_PING.
A feasible workaround for REDHAT-BUG-2342233 is to review and review your JGroups configuration to prevent logging sensitive details.