GHSA-qqhq-8r2c-c3f5

    Dashboard / Vulnerabilities / GHSA-qqhq-8r2c-c3f5

    GHSA-qqhq-8r2c-c3f5

    Published: 15 Dec 2023Last Modified: 8 Jul 2026

    Summary: nvdApiKey is logged in debug mode

    Details: ### Summary The value of `nvdApiKey` configuration parameter is logged in clear text in debug mode. ### Details The NVD API key is a kind of secret and should be treated like other secrets when logging in debug mode. Expecting the same behavior as for several password configurations: just print `******` Note that while the NVD API Key is an access token for the NVD API - they are not that sensitive. The only thing an NVD API Token grants is a higher rate limit when making calls to publicly available data. The data available from the NVD API is the same whether you have an API Key or not. ### PoC The nvdApiKey is configured to use an environment variable; when running `mvn -X dependency-check:check` the clear value is logged twice. ### Impact The NVD API key is a kind of secret and should not be exposed. If stolen, an attacker can use this key to obtain already public information.

    Affected packages

    Package

    Name: org.owasp:dependency-check-ant

    Purl: pkg:maven/org.owasp/dependency-check-ant

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 9.0.0
    Fixed -9.0.6

    Affected versions

    9.0.0
    9.0.1
    9.0.2
    9.0.3
    9.0.4
    9.0.5

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-qqhq-8r2c-c3f5 | CVE-DB