{"id":"GHSA-frxm-v7q3-v2wv","summary":"Insertion of Sensitive Information into Log File in OWASP DependencyCheck","details":"DependencyCheck for Maven 9.0.0 to 9.0.6, for CLI version 9.0.0 to 9.0.5, and for Ant versions 9.0.0 to 9.0.5, when used in debug mode, allows an attacker to recover the NVD API Key from a log file.","aliases":["CVE-2024-23686","GHSA-qqhq-8r2c-c3f5"],"modified":"2026-05-06T12:41:54.152746459Z","published":"2024-01-20T00:30:27Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2024-01-23T14:36:57Z","nvd_published_at":"2024-01-19T22:15:08Z","cwe_ids":["CWE-532"]},"references":[{"type":"WEB","url":"https://github.com/jeremylong/DependencyCheck/security/advisories/GHSA-qqhq-8r2c-c3f5"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-23686"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-qqhq-8r2c-c3f5"},{"type":"PACKAGE","url":"https://github.com/jeremylong/DependencyCheck"},{"type":"WEB","url":"https://vulncheck.com/advisories/vc-advisory-GHSA-qqhq-8r2c-c3f5"}],"affected":[{"package":{"name":"org.owasp:dependency-check-ant","ecosystem":"Maven","purl":"pkg:maven/org.owasp/dependency-check-ant"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"9.0.0"},{"fixed":"9.0.6"}]}],"versions":["9.0.0","9.0.1","9.0.2","9.0.3","9.0.4","9.0.5"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/01/GHSA-frxm-v7q3-v2wv/GHSA-frxm-v7q3-v2wv.json"}},{"package":{"name":"org.owasp:dependency-check-cli","ecosystem":"Maven","purl":"pkg:maven/org.owasp/dependency-check-cli"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"9.0.0"},{"fixed":"9.0.6"}]}],"versions":["9.0.0","9.0.1","9.0.2","9.0.3","9.0.4","9.0.5"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/01/GHSA-frxm-v7q3-v2wv/GHSA-frxm-v7q3-v2wv.json"}},{"package":{"name":"org.owasp:dependency-check-maven","ecosystem":"Maven","purl":"pkg:maven/org.owasp/dependency-check-maven"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"9.0.0"},{"fixed":"9.0.6"}]}],"versions":["9.0.0","9.0.1","9.0.2","9.0.3","9.0.4","9.0.5"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/01/GHSA-frxm-v7q3-v2wv/GHSA-frxm-v7q3-v2wv.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"}]}