CVE-2023-5384: Infinispan

Low severity, CVSS 2.7. EPSS: 0.5% chance of exploitation in the next 30 days.

A flaw was found in Infinispan. When serializing the configuration for a cache to XML/JSON/YAML, which contains credentials (JDBC store with connection pooling, remote store), the credentials are returned in clear text as part of the configuration.

Affected products

  • Infinispan Infinispan: affected versions not specified
  • Red Hat Data Grid: before 8.4.6 (fixed in 8.4.6)
  • Red Hat JBoss Data Grid: affected versions not specified

Published 2023-12-18. Last modified 2026-06-17.