CVE-2025-5731: Infinispan CLI vulnerable to Generation of Error Message Containing Sensitive Information
(updated )
A flaw was found in Infinispan CLI. A sensitive password, decoded from a Base64-encoded Kubernetes secret, is processed in plaintext and included in a command string that may expose the data in an error message when a command is not found.
References
Code Behaviors & Features
Detect and mitigate CVE-2025-5731 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →