CVE-2025-0736

A flaw was found in Infinispan, when using JGroups with JDBC_PING. This issue occurs when an application inadvertently exposes sensitive information, such as configuration details or credentials, through logging mechanisms. This exposure can lead to unauthorized access and exploitation by malicious actors.
Configurations

No configuration.

History

12 Mar 2025, 04:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2025:2663 -
Summary
  • (es) Se encontró una falla en Infinispan al usar JGroups con JDBC_PING. Este problema ocurre cuando una aplicación expone inadvertidamente información confidencial, como detalles de configuración o credenciales, a través de mecanismos de registro. Esta exposición puede provocar acceso no autorizado y explotación por parte de actores maliciosos.

28 Jan 2025, 09:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-28 09:15

Updated : 2025-03-12 04:15


NVD link : CVE-2025-0736

Mitre link : CVE-2025-0736

CVE.ORG link : CVE-2025-0736


JSON object : View

Products Affected

No product.

CWE
CWE-532

Insertion of Sensitive Information into Log File