CVE-2025-5731: Infinispan

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

A flaw was found in Infinispan CLI. A sensitive password, decoded from a Base64-encoded Kubernetes secret, is processed in plaintext and included in a command string that may expose the data in an error message when a command is not found.

Affected products

  • Infinispan Infinispan: affected versions not specified
  • Red Hat Data Grid: version 8.5.4 only
  • Red Hat JBoss Enterprise Application Platform: version 7.0.0 only; version 8.0.0 only
  • Red Hat JBoss Enterprise Application Platform Expansion Pack: affected versions not specified

Published 2025-06-26. Last modified 2026-06-17.