A vulnerability has been identified in Infinispan where sensitive credentials, such as database usernames and passwords, are logged when using JGroups with JDBC_PING. If a misconfiguration (such as an unresolved external_addr) occurs, the logging mechanism records connection details, including credentials, in plaintext. This issue can lead to credential exposure, potentially allowing unauthorized access if logs are accessible to low-privileged users or attackers.
This issue has been addressed in the following products: Red Hat Data Grid Via RHSA-2025:2663 https://access.redhat.com/errata/RHSA-2025:2663