GHSA-qqhq-8r2c-c3f5
Dashboard / Vulnerabilities / GHSA-qqhq-8r2c-c3f5
GHSA-qqhq-8r2c-c3f5
Summary: nvdApiKey is logged in debug mode
Details: ### Summary The value of `nvdApiKey` configuration parameter is logged in clear text in debug mode. ### Details The NVD API key is a kind of secret and should be treated like other secrets when logging in debug mode. Expecting the same behavior as for several password configurations: just print `******` Note that while the NVD API Key is an access token for the NVD API - they are not that sensitive. The only thing an NVD API Token grants is a higher rate limit when making calls to publicly available data. The data available from the NVD API is the same whether you have an API Key or not. ### PoC The nvdApiKey is configured to use an environment variable; when running `mvn -X dependency-check:check` the clear value is logged twice. ### Impact The NVD API key is a kind of secret and should not be exposed. If stolen, an attacker can use this key to obtain already public information.
References: https://github.com/jeremylong/DependencyCheck/security/advisories/GHSA-qqhq-8r2c-c3f5, https://github.com/jeremylong/DependencyCheck
Affected packages
Package
Name: org.owasp:dependency-check-ant
Purl: pkg:maven/org.owasp/dependency-check-ant
Affected ranges
Type: ECOSYSTEM
Events:
