CVE-2024-23686

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-23686
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-23686.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-23686
Aliases
Published
2024-01-19T22:15:08Z
Modified
2024-06-06T14:28:24.588578Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
[none]
Details

DependencyCheck for Maven 9.0.0 to 9.0.6, for CLI version 9.0.0 to 9.0.5, and for Ant versions 9.0.0 to 9.0.5, when used in debug mode, allows an attacker to recover the NVD API Key from a log file.

References

Affected packages

Git / github.com/jeremylong/dependencycheck

Affected ranges

Type
GIT
Repo
https://github.com/jeremylong/dependencycheck
Events

Affected versions

v9.*

v9.0.0
v9.0.1
v9.0.3
v9.0.4
v9.0.5