Path to dependency file: /jetty-infinispan/infinispan-remote-query/pom.xml
Path to vulnerable library: /home/wss-scanner/.m2/repository/org/infinispan/infinispan-core/9.4.8.Final/infinispan-core-9.4.8.Final.jar,/home/wss-scanner/.m2/repository/org/infinispan/infinispan-core/9.4.8.Final/infinispan-core-9.4.8.Final.jar,/home/wss-scanner/.m2/repository/org/infinispan/infinispan-core/9.4.8.Final/infinispan-core-9.4.8.Final.jar,/home/wss-scanner/.m2/repository/org/infinispan/infinispan-core/9.4.8.Final/infinispan-core-9.4.8.Final.jar
Path to dependency file: /tests/test-sessions/test-infinispan-sessions/pom.xml
Path to vulnerable library: /home/wss-scanner/.m2/repository/org/infinispan/infinispan-client-hotrod/9.4.8.Final/infinispan-client-hotrod-9.4.8.Final.jar,/home/wss-scanner/.m2/repository/org/infinispan/infinispan-client-hotrod/9.4.8.Final/infinispan-client-hotrod-9.4.8.Final.jar
Path to dependency file: /jetty-infinispan/infinispan-common/pom.xml
Path to vulnerable library: /home/wss-scanner/.m2/repository/org/infinispan/infinispan-commons/9.4.8.Final/infinispan-commons-9.4.8.Final.jar,/home/wss-scanner/.m2/repository/org/infinispan/infinispan-commons/9.4.8.Final/infinispan-commons-9.4.8.Final.jar,/home/wss-scanner/.m2/repository/org/infinispan/infinispan-commons/9.4.8.Final/infinispan-commons-9.4.8.Final.jar,/home/wss-scanner/.m2/repository/org/infinispan/infinispan-commons/9.4.8.Final/infinispan-commons-9.4.8.Final.jar
A flaw was found in Infinispan. When serializing the configuration for a cache to XML/JSON/YAML, which contains credentials (JDBC store with connection pooling, remote store), the credentials are returned in clear text as part of the configuration.
CVE-2023-5384 - High Severity Vulnerability
Vulnerable Libraries - infinispan-core-9.4.8.Final.jar, infinispan-client-hotrod-9.4.8.Final.jar, infinispan-commons-9.4.8.Final.jar
infinispan-core-9.4.8.Final.jar
Infinispan core module
Library home page: http://www.jboss.org
Path to dependency file: /jetty-infinispan/infinispan-remote-query/pom.xml
Path to vulnerable library: /home/wss-scanner/.m2/repository/org/infinispan/infinispan-core/9.4.8.Final/infinispan-core-9.4.8.Final.jar,/home/wss-scanner/.m2/repository/org/infinispan/infinispan-core/9.4.8.Final/infinispan-core-9.4.8.Final.jar,/home/wss-scanner/.m2/repository/org/infinispan/infinispan-core/9.4.8.Final/infinispan-core-9.4.8.Final.jar,/home/wss-scanner/.m2/repository/org/infinispan/infinispan-core/9.4.8.Final/infinispan-core-9.4.8.Final.jar
Dependency Hierarchy: - :x: **infinispan-core-9.4.8.Final.jar** (Vulnerable Library)
infinispan-client-hotrod-9.4.8.Final.jar
Infinispan Hot Rod Client
Library home page: http://www.jboss.org
Path to dependency file: /tests/test-sessions/test-infinispan-sessions/pom.xml
Path to vulnerable library: /home/wss-scanner/.m2/repository/org/infinispan/infinispan-client-hotrod/9.4.8.Final/infinispan-client-hotrod-9.4.8.Final.jar,/home/wss-scanner/.m2/repository/org/infinispan/infinispan-client-hotrod/9.4.8.Final/infinispan-client-hotrod-9.4.8.Final.jar
Dependency Hierarchy: - :x: **infinispan-client-hotrod-9.4.8.Final.jar** (Vulnerable Library)
infinispan-commons-9.4.8.Final.jar
Infinispan Commons
Library home page: http://www.jboss.org
Path to dependency file: /jetty-infinispan/infinispan-common/pom.xml
Path to vulnerable library: /home/wss-scanner/.m2/repository/org/infinispan/infinispan-commons/9.4.8.Final/infinispan-commons-9.4.8.Final.jar,/home/wss-scanner/.m2/repository/org/infinispan/infinispan-commons/9.4.8.Final/infinispan-commons-9.4.8.Final.jar,/home/wss-scanner/.m2/repository/org/infinispan/infinispan-commons/9.4.8.Final/infinispan-commons-9.4.8.Final.jar,/home/wss-scanner/.m2/repository/org/infinispan/infinispan-commons/9.4.8.Final/infinispan-commons-9.4.8.Final.jar
Dependency Hierarchy: - infinispan-query-9.4.8.Final.jar (Root Library) - infinispan-core-9.4.8.Final.jar - :x: **infinispan-commons-9.4.8.Final.jar** (Vulnerable Library)
Found in HEAD commit: 4e083d2729623144f1c1a52770c6f85d6a4f3b13
Found in base branch: master
Vulnerability Details
A flaw was found in Infinispan. When serializing the configuration for a cache to XML/JSON/YAML, which contains credentials (JDBC store with connection pooling, remote store), the credentials are returned in clear text as part of the configuration.
Publish Date: 2023-12-18
URL: CVE-2023-5384
CVSS 3 Score Details (7.2)
Base Score Metrics: - Exploitability Metrics: - Attack Vector: Network - Attack Complexity: Low - Privileges Required: High - User Interaction: None - Scope: Unchanged - Impact Metrics: - Confidentiality Impact: High - Integrity Impact: High - Availability Impact: High
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Origin: https://github.com/advisories/GHSA-gg57-587f-h5v6
Release Date: 2023-12-18
Fix Resolution (org.infinispan:infinispan-commons): 12.0.0.Dev03
Direct dependency fix Resolution (org.infinispan:infinispan-query): 9.4.9.Final
Step up your Open Source Security Game with Mend here