GHSA-frxm-v7q3-v2wv
Dashboard / Vulnerabilities / GHSA-frxm-v7q3-v2wv
GHSA-frxm-v7q3-v2wv
Summary: Insertion of Sensitive Information into Log File in OWASP DependencyCheck
Details: DependencyCheck for Maven 9.0.0 to 9.0.6, for CLI version 9.0.0 to 9.0.5, and for Ant versions 9.0.0 to 9.0.5, when used in debug mode, allows an attacker to recover the NVD API Key from a log file.
References: https://github.com/jeremylong/DependencyCheck/security/advisories/GHSA-qqhq-8r2c-c3f5, https://nvd.nist.gov/vuln/detail/CVE-2024-23686, https://github.com/advisories/GHSA-qqhq-8r2c-c3f5, https://github.com/jeremylong/DependencyCheck, https://vulncheck.com/advisories/vc-advisory-GHSA-qqhq-8r2c-c3f5
Affected packages
Package
Name: org.owasp:dependency-check-ant
Purl: pkg:maven/org.owasp/dependency-check-ant
Affected ranges
Type: ECOSYSTEM
Events:
