maven package report

Is org.infinispan:infinispan-cachestore-jdbc-common safe?

1 known vulnerability, worst severity MODERATE.

cvss
7.2

how bad it is if exploited, out of 10

epss
0.50%

chance of exploitation in the next 30 days

xyz score
not scored

CyberXYZ composite, out of 10

fig. 01 — GHSA-gg57-587f-h5v6, the advisory selected below

// advisories

GHSA-gg57-587f-h5v6

MODERATECVE-2023-5384

A flaw was found in Infinispan. When serializing the configuration for a cache to XML/JSON/YAML, which contains credentials (JDBC store with connection pooling, remote store), the credentials are returned in clear text as part of the configuration.

Affected
< 14.0.25.Final, >= 15.0.0.Dev01, < 15.0.0.Dev07
Fixed in
14.0.25.Final
Weakness
CWE-312
Published
2023-12-28
Source
github

GHSANVDMITREreferencereferencereferencereferencereferencereferencereferencereferencereference


// ai model usage

Tracked for PyPI packages. HuggingFace models declare Python dependencies, so maven packages are not covered.


Checked 2026-09-22 at 01:56 UTC. The most recent advisory here was published 2023-12-28. Updated continuously from NVD, GHSA, OSV and CNA feeds.

Think a verdict here is wrong? Tell us — we respond within 2 business days.
Is org.infinispan:infinispan-cachestore-jdbc-common safe? maven package security report | CyberXYZ