uthrasri / G3_Jetty

Other
0 stars 0 forks source link

CVE-2023-5384 (High) detected in multiple libraries #104

Open mend-bolt-for-github[bot] opened 3 days ago

mend-bolt-for-github[bot] commented 3 days ago

CVE-2023-5384 - High Severity Vulnerability

Vulnerable Libraries - infinispan-core-9.4.8.Final.jar, infinispan-client-hotrod-9.4.8.Final.jar, infinispan-commons-9.4.8.Final.jar

infinispan-core-9.4.8.Final.jar

Infinispan core module

Library home page: http://www.jboss.org

Path to dependency file: /jetty-infinispan/infinispan-remote-query/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/infinispan/infinispan-core/9.4.8.Final/infinispan-core-9.4.8.Final.jar,/home/wss-scanner/.m2/repository/org/infinispan/infinispan-core/9.4.8.Final/infinispan-core-9.4.8.Final.jar,/home/wss-scanner/.m2/repository/org/infinispan/infinispan-core/9.4.8.Final/infinispan-core-9.4.8.Final.jar,/home/wss-scanner/.m2/repository/org/infinispan/infinispan-core/9.4.8.Final/infinispan-core-9.4.8.Final.jar

Dependency Hierarchy: - :x: **infinispan-core-9.4.8.Final.jar** (Vulnerable Library)

infinispan-client-hotrod-9.4.8.Final.jar

Infinispan Hot Rod Client

Library home page: http://www.jboss.org

Path to dependency file: /tests/test-sessions/test-infinispan-sessions/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/infinispan/infinispan-client-hotrod/9.4.8.Final/infinispan-client-hotrod-9.4.8.Final.jar,/home/wss-scanner/.m2/repository/org/infinispan/infinispan-client-hotrod/9.4.8.Final/infinispan-client-hotrod-9.4.8.Final.jar

Dependency Hierarchy: - :x: **infinispan-client-hotrod-9.4.8.Final.jar** (Vulnerable Library)

infinispan-commons-9.4.8.Final.jar

Infinispan Commons

Library home page: http://www.jboss.org

Path to dependency file: /jetty-infinispan/infinispan-common/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/infinispan/infinispan-commons/9.4.8.Final/infinispan-commons-9.4.8.Final.jar,/home/wss-scanner/.m2/repository/org/infinispan/infinispan-commons/9.4.8.Final/infinispan-commons-9.4.8.Final.jar,/home/wss-scanner/.m2/repository/org/infinispan/infinispan-commons/9.4.8.Final/infinispan-commons-9.4.8.Final.jar,/home/wss-scanner/.m2/repository/org/infinispan/infinispan-commons/9.4.8.Final/infinispan-commons-9.4.8.Final.jar

Dependency Hierarchy: - infinispan-query-9.4.8.Final.jar (Root Library) - infinispan-core-9.4.8.Final.jar - :x: **infinispan-commons-9.4.8.Final.jar** (Vulnerable Library)

Found in HEAD commit: 4e083d2729623144f1c1a52770c6f85d6a4f3b13

Found in base branch: master

Vulnerability Details

A flaw was found in Infinispan. When serializing the configuration for a cache to XML/JSON/YAML, which contains credentials (JDBC store with connection pooling, remote store), the credentials are returned in clear text as part of the configuration.

Publish Date: 2023-12-18

URL: CVE-2023-5384

CVSS 3 Score Details (7.2)

Base Score Metrics: - Exploitability Metrics: - Attack Vector: Network - Attack Complexity: Low - Privileges Required: High - User Interaction: None - Scope: Unchanged - Impact Metrics: - Confidentiality Impact: High - Integrity Impact: High - Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: https://github.com/advisories/GHSA-gg57-587f-h5v6

Release Date: 2023-12-18

Fix Resolution (org.infinispan:infinispan-commons): 12.0.0.Dev03

Direct dependency fix Resolution (org.infinispan:infinispan-query): 9.4.9.Final


Step up your Open Source Security Game with Mend here