Medium severity5.5NVD Advisory· Published Jun 26, 2025· Updated Jun 17, 2026
CVE-2025-5731
CVE-2025-5731
Description
A flaw was found in Infinispan CLI. A sensitive password, decoded from a Base64-encoded Kubernetes secret, is processed in plaintext and included in a command string that may expose the data in an error message when a command is not found.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.infinispan:infinispan-cli-clientMaven | <= 16.0.0.Dev01 | — |
Affected products
17- Red Hat/Red Hat Data Grid 8.5.4v5cpe:/a:redhat:jboss_data_grid:8
cpe:/a:redhat:jboss_enterprise_application_platform:7+ 3 more
- cpe:/a:redhat:jboss_enterprise_application_platform:7
- cpe:/a:redhat:jboss_enterprise_application_platform:8
- cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:jboss_enterprise_application_platform:8.0.0:*:*:*:*:*:*:*
cpe:/a:redhat:jbosseapxp+ 1 more
- cpe:/a:redhat:jbosseapxp
- cpe:2.3:a:redhat:jboss_enterprise_application_platform_expansion_pack:-:*:*:*:*:*:*:*
- cpe:2.3:a:infinispan:infinispan:-:*:*:*:*:*:*:*
- osv-coords7 versionspkg:apk/chainguard/infinispan-16.0pkg:apk/chainguard/infinispan-16.1pkg:apk/chainguard/infinispan-16.2pkg:apk/wolfi/infinispan-16.0pkg:apk/wolfi/infinispan-16.1pkg:apk/wolfi/infinispan-16.2pkg:maven/org.infinispan/infinispan-cli-client
< 16.0.5-r0+ 6 more
- (no CPE)range: < 16.0.5-r0
- (no CPE)range: < 16.1.0-r0
- (no CPE)range: < 0
- (no CPE)range: < 16.0.5-r0
- (no CPE)range: < 16.1.0-r0
- (no CPE)range: < 0
- (no CPE)range: <= 16.0.0.Dev01
- Range: 0
Patches
Vulnerability mechanics
References
5- access.redhat.com/errata/RHSA-2025:10130nvdThird Party AdvisoryWEB
- access.redhat.com/security/cve/CVE-2025-5731nvdThird Party AdvisoryWEB
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingThird Party AdvisoryWEB
- github.com/advisories/GHSA-cqm8-rg2p-jfcfghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2025-5731ghsaADVISORY
News mentions
0No linked articles in our index yet.