Description
The CVEProject/cve-services is an open source project used to operate the CVE services api. In versions up to and including 1.1.1 the `org.conroller.js` code would erroneously log user secrets. This has been resolved in commit `46d98f2b` and should be available in subsequent versions of the software. Users of the software are advised to manually apply the `46d98f2b` commit or to update when a new version becomes available. As a workaround users should inspect their logs and remove logged secrets as appropriate.
References (2)
Core 2
Core References
Third Party Advisory x_refsource_confirm
https://github.com/CVEProject/cve-services/security/advisories/GHSA-rhj9-qx37-7m2m
Patch, Third Party Advisory x_refsource_misc
https://github.com/CVEProject/cve-services/commit/46d98f2b1427fc6ba1c2bc443dc6688fd400f1f4
Scores
CVSS v3
5.3
EPSS
0.0030
EPSS Percentile
53.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-532
Status
published
Products (1)
cve/cve-services
< 1.1.1
Published
Apr 21, 2022
Tracked Since
Feb 18, 2026