A flaw was found in Infinispan. When serializing the configuration for a cache to XML/JSON/YAML, which contains credentials (JDBC store with connection pooling, remote store), the credentials are returned in clear text as part of the configuration.
{
"nvd_published_at": "2023-12-18T14:15:11Z",
"severity": "MODERATE",
"github_reviewed_at": "2024-09-16T22:00:09Z",
"github_reviewed": true,
"cwe_ids": [
"CWE-312"
]
}