5.3
CVE-2024-23686
- EPSS 0.53%
- Veröffentlicht 19.01.2024 22:15:08
- Zuletzt bearbeitet 29.11.2025 02:15:52
- Quelle disclosure@vulncheck.com
- CVE-Watchlists
- Unerledigt
DependencyCheck for Maven 9.0.0 to 9.0.6, for CLI version 9.0.0 to 9.0.5, and for Ant versions 9.0.0 to 9.0.5, when used in debug mode, allows an attacker to recover the NVD API Key from a log file.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Owasp ≫ Dependency-check SwPlatformant Version >= 9.0.0 <= 9.0.5
Owasp ≫ Dependency-check SwPlatformcli Version >= 9.0.0 <= 9.0.5
Owasp ≫ Dependency-check SwPlatformmaven Version >= 9.0.0 < 9.0.6
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.53% | 0.664 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|
CWE-532 Insertion of Sensitive Information into Log File
The product writes sensitive information to a log file.