CVE-2025-5731: Infinispan
Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.
A flaw was found in Infinispan CLI. A sensitive password, decoded from a Base64-encoded Kubernetes secret, is processed in plaintext and included in a command string that may expose the data in an error message when a command is not found.
Affected products
- Infinispan Infinispan: affected versions not specified
- Red Hat Data Grid: version 8.5.4 only
- Red Hat JBoss Enterprise Application Platform: version 7.0.0 only; version 8.0.0 only
- Red Hat JBoss Enterprise Application Platform Expansion Pack: affected versions not specified
Published 2025-06-26. Last modified 2026-06-17.