org.infinispan:infinispan-core@5.2.7-wolfc-1 vulnerabilities

  • latest version

    16.0.0.Dev06

  • latest non vulnerable version

  • first published

    14 years ago

  • latest version published

    22 days ago

  • licenses detected

  • package registry

  • Direct Vulnerabilities

    Known vulnerabilities in the org.infinispan:infinispan-core package. This does not include vulnerabilities belonging to this package’s dependencies.

    Fix vulnerabilities automatically

    Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Insertion of Sensitive Information into Log File

    org.infinispan:infinispan-core is a data grid platform and highly scalable NoSQL cloud data store.

    Affected versions of this package are vulnerable to Insertion of Sensitive Information into Log File when using JDBC_PING with JGroups. An attacker can gain unauthorized access and potentially exploit exposed sensitive information, such as configuration details or credentials, through logging mechanisms.

    How to fix Insertion of Sensitive Information into Log File?

    Upgrade org.infinispan:infinispan-core to version 14.0.34.Final, 15.0.13.Final, 15.1.5.Final or higher.

    [,14.0.34.Final)[15.0.0.CR1,15.0.13.Final)[15.1.0.Dev01,15.1.5.Final)