5.3
CVE-2024-23686
- EPSS 0.6%
- Veröffentlicht 19.01.2024 22:15:08
- Zuletzt bearbeitet 14.07.2026 23:17:16
- Erkennungen
DependencyCheck Debug Mode Logging of NVD API Key
DependencyCheck for Maven 9.0.0 to 9.0.6, for CLI version 9.0.0 to 9.0.5, and for Ant versions 9.0.0 to 9.0.5, when used in debug mode, allows an attacker to recover the NVD API Key from a log file.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Owasp ≫ Dependency-check SwPlatform ant Version >= 9.0.0 <= 9.0.5
Owasp ≫ Dependency-check SwPlatform cli Version >= 9.0.0 <= 9.0.5
Owasp ≫ Dependency-check SwPlatform maven Version >= 9.0.0 < 9.0.6
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.6% | 0.439 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|
| CISA-ADP | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|
CWE-532 Insertion of Sensitive Information into Log File
The product writes sensitive information to a log file.
https://github.com/advisories/GHSA-qqhq-8r2c-c3f5
https://github.com/jeremylong/DependencyCheck/security/advisories/GHSA-qqhq-8r2c-c3f5
https://vulncheck.com/advisories/vc-advisory-GHSA-qqhq-8r2c-c3f5