CVE-2024-23686

MEDIUM

Owasp Dependency-check < 9.0.5 - Log Information Exposure

Title source: rule
STIX 2.1

Description

DependencyCheck for Maven 9.0.0 to 9.0.6, for CLI version 9.0.0 to 9.0.5, and for Ant versions 9.0.0 to 9.0.5, when used in debug mode, allows an attacker to recover the NVD API Key from a log file.

References (3)

Core 3
Core References
Third Party Advisory third-party-advisory
https://github.com/advisories/GHSA-qqhq-8r2c-c3f5
Third Party Advisory third-party-advisory
https://vulncheck.com/advisories/vc-advisory-GHSA-qqhq-8r2c-c3f5

Scores

CVSS v3 5.3
EPSS 0.0065
EPSS Percentile 70.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-532
Status published
Products (5)
org.owasp/dependency-check-ant 9.0.0 - 9.0.6Maven
org.owasp/dependency-check-cli 9.0.0 - 9.0.6Maven
org.owasp/dependency-check-maven 9.0.0 - 9.0.6Maven
owasp/dependency-check 9.0.0 - 9.0.5 (2 CPE variants)
owasp/dependency-check 9.0.0 - 9.0.6
Published Jan 19, 2024
Tracked Since Feb 18, 2026