CVE-2024-23686

MEDIUM

OWASP Dependency-Check 9.0.0-9.0.6 - Sensitive Information Exposure in Debug Log

Title source: llm
STIX 2.1

Description

DependencyCheck for Maven 9.0.0 to 9.0.6, for CLI version 9.0.0 to 9.0.5, and for Ant versions 9.0.0 to 9.0.5, when used in debug mode, allows an attacker to recover the NVD API Key from a log file.

References (3)

Core 3
Core References
Third Party Advisory third-party-advisory
https://github.com/advisories/GHSA-qqhq-8r2c-c3f5
Third Party Advisory third-party-advisory
https://vulncheck.com/advisories/vc-advisory-GHSA-qqhq-8r2c-c3f5

Scores

CVSS v3 5.3
EPSS 0.0060
EPSS Percentile 43.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-532
Status published
Products (5)
org.owasp/dependency-check-ant 9.0.0 - 9.0.6Maven
org.owasp/dependency-check-cli 9.0.0 - 9.0.6Maven
org.owasp/dependency-check-maven 9.0.0 - 9.0.6Maven
owasp/dependency-check 9.0.0 - 9.0.5 (2 CPE variants)
owasp/dependency-check 9.0.0 - 9.0.6
Published Jan 19, 2024
Tracked Since Feb 18, 2026